2026 CVE Vulnerabilities
51,441 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4241 | MEDIUM | 6.3 | 0.2% | Mar 16, 2026 | A vulnerability was identified in itsourcecode College Management System 1.0. The impacted element is an unknown functio... |
| CVE-2026-4238 | MEDIUM | 4.7 | 0.2% | Mar 16, 2026 | A vulnerability has been found in itsourcecode College Management System 1.0. This issue affects some unknown processing... |
| CVE-2026-4234 | MEDIUM | 6.3 | 0.2% | Mar 16, 2026 | A security flaw has been discovered in SSCMS 7.4.0. This vulnerability affects unknown code of the file SitesAddControll... |
| CVE-2026-4233 | MEDIUM | 4.3 | 0.4% | Mar 16, 2026 | A vulnerability was identified in ThingsGateway 12. This affects an unknown part of the file /api/file/download. The man... |
| CVE-2026-4230 | MEDIUM | 6.3 | 0.2% | Mar 16, 2026 | A vulnerability has been found in vanna-ai vanna up to 2.0.2. Affected is the function update_sql of the file src/vanna/... |
| CVE-2026-4216 | MEDIUM | 5.3 | 0.1% | Mar 16, 2026 | A weakness has been identified in i-SENS SmartLog App up to 2.6.8 on Android. This affects an unknown function of the co... |
| CVE-2026-4215 | MEDIUM | 6.3 | 0.2% | Mar 16, 2026 | A security flaw has been discovered in FlowCI flow-core-x up to 1.23.01. The impacted element is the function Save of th... |
| CVE-2026-4199 | MEDIUM | 5.3 | 0.6% | Mar 16, 2026 | A vulnerability was identified in bazinga012 mcp_code_executor up to 0.3.0. Affected by this issue is the function insta... |
| CVE-2026-4198 | MEDIUM | 5.3 | 0.6% | Mar 16, 2026 | A vulnerability was determined in hypermodel-labs mcp-server-auto-commit 1.0.0. Affected by this vulnerability is the fu... |
| CVE-2026-4192 | MEDIUM | 6.3 | 1.3% | Mar 16, 2026 | A vulnerability has been found in AvinashBole quip-mcp-server 1.0.0. Affected by this vulnerability is the function setu... |
| CVE-2026-4189 | MEDIUM | 4.7 | 0.3% | Mar 16, 2026 | A weakness has been identified in phpipam up to 1.7.4. The impacted element is an unknown function of the file app/admin... |
| CVE-2026-4187 | MEDIUM | 5.5 | 0.5% | Mar 16, 2026 | A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Impacted is an unknown function of... |
| CVE-2026-4185 | MEDIUM | 6.3 | 0.3% | Mar 16, 2026 | A vulnerability was found in GPAC up to 2.5-DEV-rev2167-gcc9d617c0-master. This vulnerability affects the function swf_d... |
| CVE-2026-4179 | MEDIUM | 6.1 | 0.2% | Mar 16, 2026 | Issues in stm32 USB device driver (drivers/usb/device/usb_dc_stm32.c) can lead to an infinite while loop. |
| CVE-2026-4175 | MEDIUM | 5.1 | 0.3% | Mar 16, 2026 | A vulnerability was determined in Aureus ERP up to 1.3.0-BETA2. The affected element is an unknown function of the file ... |
| CVE-2026-4173 | MEDIUM | 6.3 | 0.2% | Mar 16, 2026 | A flaw has been found in CodePhiliaX Chat2DB up to 0.3.7. This vulnerability affects the function exportTable/exportTabl... |
| CVE-2026-4171 | MEDIUM | 6.3 | 0.3% | Mar 16, 2026 | A security vulnerability has been detected in CodeGenieApp serverless-express up to 4.17.1. Affected by this issue is so... |
| CVE-2026-4169 | MEDIUM | 4.8 | 0.2% | Mar 16, 2026 | A security flaw has been discovered in Tecnick TCExam up to 16.6.0. Affected is the function F_xml_export_users of the f... |
| CVE-2026-3227 | MEDIUM | 6.8 | 1.1% | Mar 16, 2026 | A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to imprope... |
| CVE-2026-3111 | MEDIUM | 6.9 | 0.3% | Mar 16, 2026 | Insecure Direct Object Reference (IDOR) vulnerability in Campus Educativa specifically at the endpoint '/archivos/usuari... |
| CVE-2026-3024 | MEDIUM | 5.4 | 0.1% | Mar 16, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in the Wakyma web application, specifically in the endpoint 'vets.wakyma... |
| CVE-2026-3022 | MEDIUM | 6.5 | 0.2% | Mar 16, 2026 | Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wa... |
| CVE-2026-3021 | MEDIUM | 6.5 | 0.2% | Mar 16, 2026 | Non-relational SQL injection vulnerability (NoSQLi) in the Wakyma web application, specifically in the endpoint 'vets.wa... |
| CVE-2026-32778 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memo... |
| CVE-2026-32777 | MEDIUM | 5.5 | 0.2% | Mar 16, 2026 | libexpat before 2.7.5 allows an infinite loop while parsing DTD content. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now