2026 CVE Vulnerabilities
51,187 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33136 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS)... |
| CVE-2026-33135 | MEDIUM | 6.1 | 0.2% | Mar 20, 2026 | WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS)... |
| CVE-2026-33132 | MEDIUM | 5.3 | 0.3% | Mar 20, 2026 | ZITADEL is an open source identity management platform. Versions prior to 3.4.9 and 4.0.0 through 4.12.2 allowed users t... |
| CVE-2026-32305 | MEDIUM | 5.3 | 0.4% | Mar 20, 2026 | Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea... |
| CVE-2026-25792 | MEDIUM | 6.5 | 0.2% | Mar 20, 2026 | Greenshot is an open source Windows screenshot utility. Versions 1.3.312 and below have untrusted executable search path... |
| CVE-2026-33130 | MEDIUM | 6.5 | 0.3% | Mar 20, 2026 | Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 through 2.2.0, the fix from GHSA-vffh-c9p... |
| CVE-2026-33129 | MEDIUM | 5.9 | 0.3% | Mar 20, 2026 | H3 is a minimal H(TTP) framework. Versions 2.0.1-beta.0 through 2.0.0-rc.8 contain a Timing Side-Channel vulnerability i... |
| CVE-2026-33123 | MEDIUM | 6.5 | 0.3% | Mar 20, 2026 | pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious ... |
| CVE-2026-0677 | MEDIUM | 6.3 | 0.2% | Mar 20, 2026 | Deserialization of Untrusted Data vulnerability in TotalSuite TotalContest Lite totalcontest-lite allows Object Injectio... |
| CVE-2026-3550 | MEDIUM | 5.3 | 0.4% | Mar 20, 2026 | The RockPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.17. ... |
| CVE-2026-33192 | MEDIUM | 5.3 | 0.3% | Mar 20, 2026 | Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.... |
| CVE-2026-33080 | MEDIUM | 5.4 | 0.3% | Mar 20, 2026 | Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and ... |
| CVE-2026-33070 | MEDIUM | 4.8 | 0.4% | Mar 20, 2026 | FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, a missing-authentication vulnera... |
| CVE-2026-2432 | MEDIUM | 4.4 | 0.2% | Mar 20, 2026 | The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2026-2421 | MEDIUM | 6.5 | 0.5% | Mar 20, 2026 | The ilGhera Carta Docente for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, an... |
| CVE-2026-27625 | MEDIUM | 6.5 | 0.5% | Mar 20, 2026 | Stirling-PDF is a locally hosted web application that performs various operations on PDF files. In versions prior to 2.5... |
| CVE-2026-23277 | MEDIUM | 5.5 | 0.1% | Mar 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: teql: fix NULL pointer dereference in ip... |
| CVE-2026-23276 | MEDIUM | 5.5 | 0.1% | Mar 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: add xmit recursion limit to tunnel xmit functi... |
| CVE-2026-33065 | MEDIUM | 5.3 | 0.3% | Mar 20, 2026 | Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.... |
| CVE-2026-33061 | MEDIUM | 5.4 | 0.2% | Mar 20, 2026 | Jexactyl is a customisable game management panel and billing system. Commits after 025e8dbb0daaa04054276bda814d922cf4af5... |
| CVE-2026-33060 | MEDIUM | 5.7 | 0.3% | Mar 20, 2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Versions prior to 0.4.85 provide tools including ckan_pac... |
| CVE-2026-33056 | MEDIUM | 6.5 | 0.4% | Mar 20, 2026 | tar-rs is a tar archive reading/writing library for Rust. In versions 0.4.44 and below, when unpacking a tar archive, th... |
| CVE-2026-33022 | MEDIUM | 6.5 | 0.4% | Mar 20, 2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Versions 0.60.0 through 1.0.0... |
| CVE-2026-4476 | MEDIUM | 6.3 | 0.3% | Mar 20, 2026 | A vulnerability was found in Yi Technology YI Home Camera 2 2.1.1_20171024151200. The impacted element is an unknown fun... |
| CVE-2026-4474 | MEDIUM | 6.1 | 0.3% | Mar 20, 2026 | A flaw has been found in itsourcecode University Management System 1.0. Impacted is an unknown function of the file /adm... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now