2026 CVE Vulnerabilities
51,444 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32777 | MEDIUM | 5.5 | 0.2% | Mar 16, 2026 | libexpat before 2.7.5 allows an infinite loop while parsing DTD content. |
| CVE-2026-32776 | MEDIUM | 5.5 | 0.1% | Mar 16, 2026 | libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content. |
| CVE-2026-32774 | MEDIUM | 5.4 | 0.3% | Mar 16, 2026 | Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers... |
| CVE-2026-32772 | MEDIUM | 4.7 | 0.2% | Mar 16, 2026 | telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON ... |
| CVE-2026-32724 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the Mav... |
| CVE-2026-32719 | MEDIUM | 6.4 | 0.4% | Mar 16, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-32713 | MEDIUM | 6.5 | 0.4% | Mar 16, 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, A logic error in the PX4 Autopilot MAVLink F... |
| CVE-2026-32709 | MEDIUM | 6.8 | 0.5% | Mar 16, 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, An unauthenticated path traversal vulnerabil... |
| CVE-2026-32707 | MEDIUM | 6.1 | 0.3% | Mar 16, 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, tattu_can contains an unbounded memcpy in it... |
| CVE-2026-32705 | MEDIUM | 6.8 | 0.3% | Mar 16, 2026 | PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the BST telemetry probe writes a string term... |
| CVE-2026-32704 | MEDIUM | 6.5 | 0.2% | Mar 16, 2026 | SiYuan is a personal knowledge management system. Prior to 3.6.1, POST /api/template/renderSprig lacks model.CheckAdminR... |
| CVE-2026-32702 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c... |
| CVE-2026-32630 | MEDIUM | 5.3 | 0.3% | Mar 16, 2026 | file-type detects the file type of a file, stream, or data. From 20.0.0 to 21.3.1, a crafted ZIP file can trigger excess... |
| CVE-2026-2578 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which all... |
| CVE-2026-2491 | MEDIUM | 6.3 | 0.4% | Mar 16, 2026 | Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to... |
| CVE-2026-2476 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with... |
| CVE-2026-2463 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user perm... |
| CVE-2026-2462 | MEDIUM | 6.6 | 0.3% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI t... |
| CVE-2026-2461 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modi... |
| CVE-2026-2458 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership wh... |
| CVE-2026-2457 | MEDIUM | 4.3 | 0.1% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metada... |
| CVE-2026-2456 | MEDIUM | 5.7 | 0.2% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of respon... |
| CVE-2026-2233 | MEDIUM | 5.3 | 0.2% | Mar 16, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-26246 | MEDIUM | 4.3 | 0.2% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when process... |
| CVE-2026-25783 | MEDIUM | 4.3 | 0.3% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now