2026 CVE Vulnerabilities
51,094 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33680 | MEDIUM | 6.5 | 0.4% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.2, the `LinkSharing.ReadAll()` meth... |
| CVE-2026-33677 | MEDIUM | 6.5 | 0.3% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `GET /api/v1/projects/:proje... |
| CVE-2026-33676 | MEDIUM | 6.5 | 0.3% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, when the Vikunja API returns tas... |
| CVE-2026-33675 | MEDIUM | 5.4 | 0.3% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the migration helper functions `... |
| CVE-2026-33474 | MEDIUM | 6.5 | 0.3% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Starting in version 1.0.0-rc0 and prior to version 2.2.0... |
| CVE-2026-33473 | MEDIUM | 5.7 | 0.3% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Starting in version 0.13 and prior to version 2.2.1, any... |
| CVE-2026-29840 | MEDIUM | 5.4 | 0.2% | Mar 24, 2026 | JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function within app... |
| CVE-2026-33315 | MEDIUM | 4.3 | 0.3% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, the Caldav endpoint allows login... |
| CVE-2026-33313 | MEDIUM | 4.3 | 0.3% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, an authenticated user can read a... |
| CVE-2026-30662 | MEDIUM | 6.5 | 0.3% | Mar 24, 2026 | ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method... |
| CVE-2026-30661 | MEDIUM | 6.1 | 0.2% | Mar 24, 2026 | iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within th... |
| CVE-2026-30655 | MEDIUM | 6.5 | 0.5% | Mar 24, 2026 | SQL injection in Solicitante::resetaSenha() in esiclivre/esiclivre v0.2.2 and earlier allows unauthenticated remote atta... |
| CVE-2026-28755 | MEDIUM | 5.4 | 0.1% | Mar 24, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling o... |
| CVE-2026-28753 | MEDIUM | 6.3 | 0.3% | Mar 24, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of... |
| CVE-2026-33311 | MEDIUM | 4.7 | 0.2% | Mar 24, 2026 | DiceBear is an avatar library for designers and developers. Starting in version 5.0.0 and prior to versions 5.4.4, 6.1.4... |
| CVE-2026-4728 | MEDIUM | 6.5 | 0.2% | Mar 24, 2026 | Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
| CVE-2026-4649 | MEDIUM | 5.3 | 0.3% | Mar 24, 2026 | Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exch... |
| CVE-2026-32642 | MEDIUM | 4.3 | 0.5% | Mar 24, 2026 | Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application us... |
| CVE-2026-4754 | MEDIUM | 6.1 | 0.1% | Mar 24, 2026 | CWE-79 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. |
| CVE-2026-4752 | MEDIUM | 6.4 | 0.1% | Mar 24, 2026 | Use After Free vulnerability in No-Chicken Echo-Mate.This issue affects Echo-Mate: before V250329. |
| CVE-2026-4751 | MEDIUM | 5.3 | 0.3% | Mar 24, 2026 | NULL Pointer Dereference vulnerability in tmate-io tmate.This issue affects tmate: before 2.4.0. |
| CVE-2026-4749 | MEDIUM | 6.5 | 0.2% | Mar 24, 2026 | NVD-CWE-noinfo vulnerability in albfan miraclecast.This issue affects miraclecast: before v1.0. |
| CVE-2026-3138 | MEDIUM | 6.5 | 0.3% | Mar 24, 2026 | The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing ... |
| CVE-2026-4743 | MEDIUM | 5.2 | 0.1% | Mar 24, 2026 | NULL Pointer Dereference vulnerability in taurusxin ncmdump (src/utils modules). This vulnerability is associated with... |
| CVE-2026-4733 | MEDIUM | 5.3 | 0.2% | Mar 24, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affect... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now