2026 CVE Vulnerabilities
51,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33304 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-33303 | MEDIUM | 5.4 | 0.2% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ... |
| CVE-2026-33299 | MEDIUM | 5.4 | 0.2% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-32747 | MEDIUM | 4.9 | 0.4% | Mar 19, 2026 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the globalCopyFiles API eads source file... |
| CVE-2026-27740 | MEDIUM | 6.1 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cros... |
| CVE-2026-27570 | MEDIUM | 6.1 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox... |
| CVE-2026-27491 | MEDIUM | 4.3 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coe... |
| CVE-2026-27454 | MEDIUM | 5.3 | 0.4% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting... |
| CVE-2026-27166 | MEDIUM | 5.4 | 0.2% | Mar 19, 2026 | Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficie... |
| CVE-2026-24299 | MEDIUM | 5.3 | 0.6% | Mar 19, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz... |
| CVE-2026-3580 | MEDIUM | 4.7 | 0.1% | Mar 19, 2026 | In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bnez) by... |
| CVE-2026-3579 | MEDIUM | 5.9 | 0.3% | Mar 19, 2026 | wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The... |
| CVE-2026-32119 | MEDIUM | 4.4 | 0.2% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-25928 | MEDIUM | 6.5 | 0.5% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-25744 | MEDIUM | 6.5 | 0.2% | Mar 19, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-3503 | MEDIUM | 5.2 | 0.2% | Mar 19, 2026 | Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M mi... |
| CVE-2026-26940 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead De... |
| CVE-2026-26939 | MEDIUM | 6.5 | 0.2% | Mar 19, 2026 | Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Resp... |
| CVE-2026-26933 | MEDIUM | 5.7 | 0.2% | Mar 19, 2026 | Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Ser... |
| CVE-2026-26931 | MEDIUM | 5.7 | 0.2% | Mar 19, 2026 | Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead... |
| CVE-2026-1005 | MEDIUM | 5.3 | 0.3% | Mar 19, 2026 | Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decryptio... |
| CVE-2026-32869 | MEDIUM | 5.4 | 0.1% | Mar 19, 2026 | OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field w... |
| CVE-2026-32868 | MEDIUM | 5.4 | 0.1% | Mar 19, 2026 | OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the ... |
| CVE-2026-32866 | MEDIUM | 5.4 | 0.1% | Mar 19, 2026 | OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a us... |
| CVE-2026-4426 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now