2026 CVE Vulnerabilities
52,221 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3954 | MEDIUM | 6.5 | 0.5% | Mar 11, 2026 | A weakness has been identified in OpenBMB XAgent 1.0.0. Affected by this vulnerability is the function workspace of the ... |
| CVE-2026-3951 | MEDIUM | 4.3 | 0.3% | Mar 11, 2026 | A security flaw has been discovered in LockerProject Locker 0.0.0/0.0.1/0.1.0. Affected is the function authIsAwesome of... |
| CVE-2026-32234 | MEDIUM | 4.7 | 0.2% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32095 | MEDIUM | 5.4 | 0.1% | Mar 11, 2026 | Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.1, Plunk's image upload endpoint accepted S... |
| CVE-2026-32094 | MEDIUM | 6.5 | 0.2% | Mar 11, 2026 | Shescape is a simple shell escape library for JavaScript. Prior to 2.1.10, Shescape#escape() does not escape square-brac... |
| CVE-2026-31974 | MEDIUM | 4.3 | 0.2% | Mar 11, 2026 | OpenProject is an open-source, web-based project management software. Prior to 17.2.0, OpenProject SMTP test endpoint (P... |
| CVE-2026-31961 | MEDIUM | 5.5 | 0.1% | Mar 11, 2026 | Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains an unb... |
| CVE-2026-31960 | MEDIUM | 5.3 | 0.1% | Mar 11, 2026 | Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded r... |
| CVE-2026-31959 | MEDIUM | 5.3 | 0.1% | Mar 11, 2026 | Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains a Serv... |
| CVE-2026-31901 | MEDIUM | 5.3 | 0.2% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 ... |
| CVE-2026-24508 | MEDIUM | 5.5 | 0.1% | Mar 11, 2026 | Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerabil... |
| CVE-2026-31888 | MEDIUM | 5.3 | 0.2% | Mar 11, 2026 | Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/acc... |
| CVE-2026-31879 | MEDIUM | 5.4 | 0.1% | Mar 11, 2026 | Frappe is a full-stack web application framework. Prior to 14.100.2, 15.101.0, and 16.10.0, due to a lack of validation ... |
| CVE-2026-31878 | MEDIUM | 5 | 0.2% | Mar 11, 2026 | Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a... |
| CVE-2026-31876 | MEDIUM | 5.4 | 0.2% | Mar 11, 2026 | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS... |
| CVE-2026-24509 | MEDIUM | 5.5 | 0.1% | Mar 11, 2026 | Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerability. A l... |
| CVE-2026-31875 | MEDIUM | 5.9 | 0.4% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-31868 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-31867 | MEDIUM | 4.8 | 0.3% | Mar 11, 2026 | Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (I... |
| CVE-2026-31863 | MEDIUM | 4.4 | 0.1% | Mar 11, 2026 | Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API ca... |
| CVE-2026-31859 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in... |
| CVE-2026-0231 | MEDIUM | 5.7 | 0.2% | Mar 11, 2026 | An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obta... |
| CVE-2026-0230 | MEDIUM | 4 | 0.1% | Mar 11, 2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator t... |
| CVE-2026-3429 | MEDIUM | 4.2 | 0.3% | Mar 11, 2026 | A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to ... |
| CVE-2026-31853 | MEDIUM | 5.5 | 0.1% | Mar 11, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now