2026 CVE Vulnerabilities
51,177 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32844 | MEDIUM | 6.1 | 0.3% | Mar 20, 2026 | XinLiangCoder php_api_doc through commit 1ce5bbf contains a reflected cross-site scripting vulnerability in list_method.... |
| CVE-2026-32303 | MEDIUM | 5.9 | 0.1% | Mar 20, 2026 | Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerabilit... |
| CVE-2026-30580 | MEDIUM | 4.3 | 0.6% | Mar 20, 2026 | File Thingie 2.5.7 is vulnerable to Directory Traversal. A malicious user can leverage the "create folder from url" func... |
| CVE-2026-30579 | MEDIUM | 6.5 | 0.2% | Mar 20, 2026 | File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" function... |
| CVE-2026-30578 | MEDIUM | 6.5 | 0.2% | Mar 20, 2026 | File Thinghie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "dir" parameter of th... |
| CVE-2026-29828 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | DooTask v1.6.27 has a Cross-Site Scripting (XSS) vulnerability in the /manage/project/<id> page via the input field proj... |
| CVE-2026-22902 | MEDIUM | 6.7 | 0.5% | Mar 20, 2026 | A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator ac... |
| CVE-2026-22895 | MEDIUM | 4.8 | 0.2% | Mar 20, 2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QuFTP Service. If a remote attacker gains an admi... |
| CVE-2026-32986 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | Textpattern CMS version 4.9.0 contains a second-order cross-site scripting vulnerability that allows attackers to inject... |
| CVE-2026-33312 | MEDIUM | 5.4 | 0.2% | Mar 20, 2026 | Vikunja is an open-source self-hosted task management platform. Starting in version 0.20.2 and prior to version 2.2.0, t... |
| CVE-2026-29794 | MEDIUM | 5.3 | 0.3% | Mar 20, 2026 | Vikunja is an open-source self-hosted task management platform. Starting in version 0.8 and prior to version 2.2.0, unau... |
| CVE-2026-4485 | MEDIUM | 6.3 | 0.2% | Mar 20, 2026 | A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown functio... |
| CVE-2026-33372 | MEDIUM | 5.4 | 0.1% | Mar 20, 2026 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability e... |
| CVE-2026-33371 | MEDIUM | 4.3 | 0.2% | Mar 20, 2026 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists i... |
| CVE-2026-33370 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability e... |
| CVE-2026-33369 | MEDIUM | 4.3 | 0.2% | Mar 20, 2026 | Zimbra Collaboration (ZCS) 10.0 and 10.1 contains an LDAP injection vulnerability in the Mailbox SOAP service within a F... |
| CVE-2026-33368 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | Zimbra Collaboration Suite (ZCS) 10.0 and 10.1 contains a reflected cross-site scripting (XSS) vulnerability in the Clas... |
| CVE-2026-31382 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-s... |
| CVE-2026-31381 | MEDIUM | 5.3 | 0.3% | Mar 20, 2026 | An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callb... |
| CVE-2026-33136 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS)... |
| CVE-2026-33135 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS)... |
| CVE-2026-33132 | MEDIUM | 5.3 | 0.3% | Mar 20, 2026 | ZITADEL is an open source identity management platform. Versions prior to 3.4.9 and 4.0.0 through 4.12.2 allowed users t... |
| CVE-2026-32305 | MEDIUM | 5.3 | 0.4% | Mar 20, 2026 | Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea... |
| CVE-2026-25792 | MEDIUM | 6.5 | 0.2% | Mar 20, 2026 | Greenshot is an open source Windows screenshot utility. Versions 1.3.312 and below have untrusted executable search path... |
| CVE-2026-33130 | MEDIUM | 6.5 | 0.3% | Mar 20, 2026 | Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 through 2.2.0, the fix from GHSA-vffh-c9p... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now