2026 CVE Vulnerabilities
52,080 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22183 | MEDIUM | 5.4 | 0.2% | Mar 13, 2026 | wpDiscuz before 7.6.47 contains a stored cross-site scripting vulnerability in the inline comment preview functionality ... |
| CVE-2026-1704 | MEDIUM | 4.3 | 0.2% | Mar 13, 2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Ins... |
| CVE-2026-0835 | MEDIUM | 5.4 | 0.2% | Mar 13, 2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ... |
| CVE-2026-2581 | MEDIUM | 5.9 | 0.6% | Mar 12, 2026 | This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulne... |
| CVE-2026-1527 | MEDIUM | 4.6 | 0.3% | Mar 12, 2026 | ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject... |
| CVE-2026-32269 | MEDIUM | 6.5 | 0.3% | Mar 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32259 | MEDIUM | 6.7 | 0.1% | Mar 12, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9... |
| CVE-2026-32251 | MEDIUM | 6.5 | 0.4% | Mar 12, 2026 | Tolgee is an open-source localization platform. Prior to 3.166.3, the XML parsers used for importing Android XML resourc... |
| CVE-2026-32249 | MEDIUM | 5.5 | 0.1% | Mar 12, 2026 | Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encoun... |
| CVE-2026-32240 | MEDIUM | 6.5 | 0.2% | Mar 12, 2026 | Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: ... |
| CVE-2026-32239 | MEDIUM | 6.5 | 0.2% | Mar 12, 2026 | Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length valu... |
| CVE-2026-32245 | MEDIUM | 6.5 | 0.3% | Mar 12, 2026 | Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the... |
| CVE-2026-32237 | MEDIUM | 6.5 | 0.2% | Mar 12, 2026 | Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to ex... |
| CVE-2026-32235 | MEDIUM | 4.7 | 0.1% | Mar 12, 2026 | Backstage is an open framework for building developer portals. Prior to 0.27.1, the experimental OIDC provider in @backs... |
| CVE-2026-32230 | MEDIUM | 5.3 | 0.9% | Mar 12, 2026 | Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 , the GET /api/badge/:id/ping/:duration?... |
| CVE-2026-32142 | MEDIUM | 5.3 | 0.2% | Mar 12, 2026 | Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is... |
| CVE-2026-2376 | MEDIUM | 5.4 | 0.2% | Mar 12, 2026 | A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal ... |
| CVE-2026-32139 | MEDIUM | 5.4 | 0.2% | Mar 12, 2026 | Dataease is an open source data visualization analysis tool. In DataEase 2.10.19 and earlier, the static resource upload... |
| CVE-2026-32100 | MEDIUM | 5.3 | 0.2% | Mar 12, 2026 | Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vul... |
| CVE-2026-31890 | MEDIUM | 5.5 | 0.1% | Mar 12, 2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li... |
| CVE-2026-31873 | MEDIUM | 6.1 | 0.2% | Mar 12, 2026 | Unhead is a document head and template manager. Prior to 2.1.11, The link.href check in makeTagSafe (safe.ts) uses Strin... |
| CVE-2026-31860 | MEDIUM | 6.1 | 0.3% | Mar 12, 2026 | Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML ... |
| CVE-2026-31841 | MEDIUM | 6.5 | 0.2% | Mar 12, 2026 | Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. Prior to v2.2.0... |
| CVE-2026-29066 | MEDIUM | 6.2 | 1.0% | Mar 12, 2026 | Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs.... |
| CVE-2026-24125 | MEDIUM | 6.3 | 0.4% | Mar 12, 2026 | Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now