2026 CVE Vulnerabilities
51,327 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23249 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfs: check for deleted cursors when revalidating tw... |
| CVE-2026-30695 | MEDIUM | 6.1 | 0.2% | Mar 18, 2026 | A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access con... |
| CVE-2026-33004 | MEDIUM | 4.3 | 0.2% | Mar 18, 2026 | Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, incre... |
| CVE-2026-33003 | MEDIUM | 4.3 | 0.1% | Mar 18, 2026 | Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins co... |
| CVE-2026-2559 | MEDIUM | 5.3 | 0.2% | Mar 18, 2026 | The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... |
| CVE-2026-2512 | MEDIUM | 6.4 | 0.2% | Mar 18, 2026 | The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field meta values in all ver... |
| CVE-2026-3278 | MEDIUM | 6.1 | 0.1% | Mar 18, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks... |
| CVE-2026-32694 | MEDIUM | 6.6 | 0.3% | Mar 18, 2026 | In Juju from version 3.0.0 through 3.6.18, when a secret owner grants permissions to a secret to a grantee, the secret o... |
| CVE-2026-32692 | MEDIUM | 6.5 | 0.2% | Mar 18, 2026 | An authorization bypass vulnerability in the Vault secrets back-end implementation of Juju versions 3.1.6 through 3.6.18... |
| CVE-2026-32691 | MEDIUM | 5.3 | 0.2% | Mar 18, 2026 | A race condition in the secrets management subsystem of Juju versions 3.0.0 through 3.6.18 allows an authenticated unit ... |
| CVE-2026-23247 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This ... |
| CVE-2026-32565 | MEDIUM | 5.3 | 0.2% | Mar 18, 2026 | Missing Authorization vulnerability in Ajay Contextual Related Posts contextual-related-posts allows Exploiting Incorrec... |
| CVE-2026-1217 | MEDIUM | 5.4 | 0.2% | Mar 18, 2026 | The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2026-22321 | MEDIUM | 5.3 | 0.4% | Mar 18, 2026 | A stack-based buffer overflow in the device's Telnet/SSH CLI login routine occurs when a unauthenticated attacker send a... |
| CVE-2026-22320 | MEDIUM | 6.5 | 0.3% | Mar 18, 2026 | A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Tel... |
| CVE-2026-22319 | MEDIUM | 4.9 | 0.3% | Mar 18, 2026 | A stack-based buffer overflow in the device's file installation workflow allows a high-privileged attacker to send overs... |
| CVE-2026-22318 | MEDIUM | 4.9 | 0.3% | Mar 18, 2026 | A stack-based buffer overflow vulnerability in the device's file transfer parameter workflow allows a high-privileged at... |
| CVE-2026-22316 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | A remote attacker with user privileges for the webUI can use the setting of the TFTP Filename with a POST Request to tri... |
| CVE-2026-3512 | MEDIUM | 6.1 | 0.2% | Mar 18, 2026 | The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter... |
| CVE-2026-4366 | MEDIUM | 5.8 | 0.2% | Mar 18, 2026 | A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirect... |
| CVE-2026-33058 | MEDIUM | 6.5 | 0.3% | Mar 18, 2026 | Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQ... |
| CVE-2026-32265 | MEDIUM | 6.9 | 0.3% | Mar 18, 2026 | The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, una... |
| CVE-2026-31938 | MEDIUM | 6.1 | 0.3% | Mar 18, 2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the... |
| CVE-2026-31898 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnot... |
| CVE-2026-31891 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API acc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now