2026 CVE Vulnerabilities
51,187 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33051 | MEDIUM | 5.4 | 0.2% | Mar 20, 2026 | Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu... |
| CVE-2026-33041 | MEDIUM | 5.3 | 0.3% | Mar 20, 2026 | WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json.php exposes the appl... |
| CVE-2026-33035 | MEDIUM | 6.1 | 0.3% | Mar 20, 2026 | WWBN AVideo is an open source video platform. In versions 25.0 and below, there is a reflected XSS vulnerability that al... |
| CVE-2026-32953 | MEDIUM | 4.6 | 0.2% | Mar 20, 2026 | Tillitis TKey Client package is a Go package for a TKey client. Versions 1.2.0 and below contain a critical bug in the t... |
| CVE-2026-32947 | MEDIUM | 4.9 | 0.3% | Mar 20, 2026 | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below,... |
| CVE-2026-4468 | MEDIUM | 4.7 | 2.1% | Mar 20, 2026 | A vulnerability was determined in Comfast CF-AC100 2.6.0.8. Affected is an unknown function of the file /cgi-bin/mbox-co... |
| CVE-2026-4136 | MEDIUM | 4.3 | 0.2% | Mar 20, 2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up t... |
| CVE-2026-32941 | MEDIUM | 6.5 | 0.3% | Mar 20, 2026 | Sliver is a command and control framework that uses a custom Wireguard netstack. Versions 1.7.3 and below contain a Remo... |
| CVE-2026-32940 | MEDIUM | 6.1 | 0.3% | Mar 20, 2026 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist —... |
| CVE-2026-32938 | MEDIUM | 6.5 | 0.4% | Mar 20, 2026 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the deskto... |
| CVE-2026-32114 | MEDIUM | 4.3 | 0.2% | Mar 20, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, there is a... |
| CVE-2026-4467 | MEDIUM | 4.7 | 2.1% | Mar 20, 2026 | A vulnerability was found in Comfast CF-AC100 2.6.0.8. This impacts an unknown function of the file /cgi-bin/mbox-config... |
| CVE-2026-32937 | MEDIUM | 6.5 | 0.4% | Mar 20, 2026 | free5GC is an open source 5G core network. free5GC CHF prior to version 1.2.2 has an out-of-bounds slice access vulnerab... |
| CVE-2026-32935 | MEDIUM | 5.9 | 0.4% | Mar 20, 2026 | phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, an... |
| CVE-2026-32889 | MEDIUM | 6.5 | 0.4% | Mar 20, 2026 | tinytag is a Python library for reading audio file metadata. Version 2.2.0 allows an attacker who can supply MP3 files f... |
| CVE-2026-31869 | MEDIUM | 4.3 | 0.2% | Mar 20, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Compos... |
| CVE-2026-30891 | MEDIUM | 6.5 | 0.2% | Mar 20, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a user cou... |
| CVE-2026-30889 | MEDIUM | 4.9 | 0.3% | Mar 20, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a moderato... |
| CVE-2026-30888 | MEDIUM | 5.5 | 0.2% | Mar 20, 2026 | Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 allow a mod... |
| CVE-2026-4466 | MEDIUM | 4.7 | 2.5% | Mar 20, 2026 | A vulnerability has been found in Comfast CF-AC100 2.6.0.8. This affects an unknown function of the file /cgi-bin/mbox-c... |
| CVE-2026-4453 | MEDIUM | 4.3 | 0.2% | Mar 20, 2026 | Integer overflow in Dawn in Google Chrome on Mac prior to 146.0.7680.153 allowed a remote attacker to leak cross-origin ... |
| CVE-2026-32881 | MEDIUM | 5.3 | 0.4% | Mar 20, 2026 | ewe is a Gleam web server. ewe is a Gleam web server. Versions 0.6.0 through 3.0.4 are vulnerable to authentication bypa... |
| CVE-2026-32880 | MEDIUM | 6.4 | 0.3% | Mar 20, 2026 | ChurchCRM is an open-source church management system. Versions prior to 7.0.2 allow an admin user to edit JSON type syst... |
| CVE-2026-32812 | MEDIUM | 6.8 | 0.4% | Mar 20, 2026 | Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, unrestricted URL fetch in the SSO M... |
| CVE-2026-32828 | MEDIUM | 4.9 | 0.3% | Mar 20, 2026 | Kargo manages and automates the promotion of software artifacts. In versions 1.4.0 through 1.6.3, 1.7.0-rc.1 through 1.7... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now