2026 CVE Vulnerabilities
51,104 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4733 | MEDIUM | 5.3 | 0.2% | Mar 24, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ixray-team ixray-1.6-stcop.This issue affect... |
| CVE-2026-4626 | MEDIUM | 5.4 | 0.2% | Mar 24, 2026 | A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the fi... |
| CVE-2026-33308 | MEDIUM | 5.9 | 0.2% | Mar 24, 2026 | Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for client certificate verifi... |
| CVE-2026-3079 | MEDIUM | 6.5 | 0.3% | Mar 24, 2026 | The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_order]' ... |
| CVE-2026-33320 | MEDIUM | 6.2 | 0.2% | Mar 24, 2026 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. Starting in version ... |
| CVE-2026-33290 | MEDIUM | 4.3 | 0.2% | Mar 24, 2026 | WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.10.0, an authorization flaw in updateComment al... |
| CVE-2026-4614 | MEDIUM | 6.3 | 0.2% | Mar 24, 2026 | A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown proc... |
| CVE-2026-4056 | MEDIUM | 5.4 | 0.2% | Mar 24, 2026 | The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a miss... |
| CVE-2026-33252 | MEDIUM | 6.5 | 0.2% | Mar 24, 2026 | The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted... |
| CVE-2026-33173 | MEDIUM | 5.3 | 0.4% | Mar 24, 2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a... |
| CVE-2026-33170 | MEDIUM | 6.1 | 0.3% | Mar 24, 2026 | Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to v... |
| CVE-2026-33169 | MEDIUM | 5.3 | 0.5% | Mar 24, 2026 | Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToD... |
| CVE-2026-4066 | MEDIUM | 4.3 | 0.3% | Mar 23, 2026 | The Smart Custom Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch... |
| CVE-2026-3225 | MEDIUM | 4.3 | 0.3% | Mar 23, 2026 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized deletion of quiz question answe... |
| CVE-2026-33167 | MEDIUM | 6.1 | 0.4% | Mar 23, 2026 | Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.... |
| CVE-2026-2412 | MEDIUM | 6.5 | 0.3% | Mar 23, 2026 | The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter... |
| CVE-2026-32279 | MEDIUM | 6.8 | 0.3% | Mar 23, 2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the... |
| CVE-2026-32278 | MEDIUM | 4.8 | 0.2% | Mar 23, 2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the... |
| CVE-2026-29111 | MEDIUM | 5.5 | 0.1% | Mar 23, 2026 | systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call... |
| CVE-2026-27646 | MEDIUM | 6.1 | 0.1% | Mar 23, 2026 | OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authori... |
| CVE-2026-27183 | MEDIUM | 5.3 | 0.1% | Mar 23, 2026 | OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wrapper ... |
| CVE-2026-4597 | MEDIUM | 6.3 | 0.2% | Mar 23, 2026 | A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. Impacted is the function selectAll of the ... |
| CVE-2026-23488 | MEDIUM | 5.3 | 0.3% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the /api/v1/comment/create endpoint has an una... |
| CVE-2026-23487 | MEDIUM | 6.5 | 0.2% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.deta... |
| CVE-2026-23486 | MEDIUM | 5.3 | 0.7% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all use... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now