2026 CVE Vulnerabilities
51,359 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26004 | MEDIUM | 6.5 | 0.2% | Mar 18, 2026 | Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organi... |
| CVE-2026-25937 | MEDIUM | 6.5 | 0.3% | Mar 18, 2026 | GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malic... |
| CVE-2026-20643 | MEDIUM | 5.4 | 0.4% | Mar 17, 2026 | A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Backgrou... |
| CVE-2026-1264 | MEDIUM | 6.5 | 0.2% | Mar 17, 2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ... |
| CVE-2026-4349 | MEDIUM | 6.3 | 0.4% | Mar 17, 2026 | A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the... |
| CVE-2026-32840 | MEDIUM | 5.4 | 0.2% | Mar 17, 2026 | Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_na... |
| CVE-2026-32839 | MEDIUM | 6.5 | 0.2% | Mar 17, 2026 | Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remot... |
| CVE-2026-32838 | MEDIUM | 5.9 | 0.1% | Mar 17, 2026 | Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implemen... |
| CVE-2026-1267 | MEDIUM | 6.5 | 0.3% | Mar 17, 2026 | IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and a... |
| CVE-2026-2809 | MEDIUM | 6.7 | 0.2% | Mar 17, 2026 | Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The succe... |
| CVE-2026-3563 | MEDIUM | 5.5 | 0.3% | Mar 17, 2026 | Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an auth... |
| CVE-2026-32837 | MEDIUM | 5.1 | 0.2% | Mar 17, 2026 | miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerabi... |
| CVE-2026-32836 | MEDIUM | 6.9 | 0.2% | Mar 17, 2026 | dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled me... |
| CVE-2026-32293 | MEDIUM | 6.3 | 0.3% | Mar 17, 2026 | The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL... |
| CVE-2026-4147 | MEDIUM | 4.3 | 0.2% | Mar 17, 2026 | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is... |
| CVE-2026-28506 | MEDIUM | 4.3 | 0.2% | Mar 17, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.5.0, the events.list API endpoint, used for... |
| CVE-2026-4324 | MEDIUM | 5.4 | 0.3% | Mar 17, 2026 | A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of use... |
| CVE-2026-28563 | MEDIUM | 4.3 | 0.4% | Mar 17, 2026 | Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filt... |
| CVE-2026-26929 | MEDIUM | 6.5 | 0.4% | Mar 17, 2026 | Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filterin... |
| CVE-2026-3634 | MEDIUM | 6.5 | 0.2% | Mar 17, 2026 | A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage... |
| CVE-2026-3633 | MEDIUM | 6.5 | 0.2% | Mar 17, 2026 | A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function... |
| CVE-2026-3632 | MEDIUM | 5.5 | 0.2% | Mar 17, 2026 | A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because ... |
| CVE-2026-23241 | MEDIUM | 5.5 | 0.1% | Mar 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: audit: add missing syscalls to read class The "at"... |
| CVE-2026-4202 | MEDIUM | 4.3 | 0.2% | Mar 17, 2026 | The extension fails to verify, if an authenticated user has permissions to access to redirects resulting in exposure of ... |
| CVE-2026-32586 | MEDIUM | 5.3 | 0.2% | Mar 17, 2026 | Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now