2026 CVE Vulnerabilities
52,233 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31875 | MEDIUM | 5.9 | 0.4% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-31868 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-31867 | MEDIUM | 4.8 | 0.3% | Mar 11, 2026 | Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (I... |
| CVE-2026-31863 | MEDIUM | 4.4 | 0.1% | Mar 11, 2026 | Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API ca... |
| CVE-2026-31859 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in... |
| CVE-2026-0231 | MEDIUM | 5.7 | 0.2% | Mar 11, 2026 | An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obta... |
| CVE-2026-0230 | MEDIUM | 4 | 0.1% | Mar 11, 2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator t... |
| CVE-2026-3429 | MEDIUM | 4.2 | 0.3% | Mar 11, 2026 | A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to ... |
| CVE-2026-31853 | MEDIUM | 5.5 | 0.1% | Mar 11, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9... |
| CVE-2026-31813 | MEDIUM | 4.8 | 0.1% | Mar 11, 2026 | Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vulnerability has been i... |
| CVE-2026-30236 | MEDIUM | 4.3 | 0.2% | Mar 11, 2026 | OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when editing a project budget and... |
| CVE-2026-30235 | MEDIUM | 6.5 | 0.3% | Mar 11, 2026 | OpenProject is an open-source, web-based project management software. Prior to 17.2.0, this vulnerability occurs due to ... |
| CVE-2026-20166 | MEDIUM | 5.4 | 0.2% | Mar 11, 2026 | In Splunk Enterprise versions below 10.2.1 and 10.0.4, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.1... |
| CVE-2026-20165 | MEDIUM | 6.5 | 0.2% | Mar 11, 2026 | In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.251... |
| CVE-2026-20164 | MEDIUM | 6.5 | 0.2% | Mar 11, 2026 | In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.251... |
| CVE-2026-20162 | MEDIUM | 6.3 | 0.2% | Mar 11, 2026 | In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.9, and Splunk Cloud Platform versions below 10.2.2510... |
| CVE-2026-20118 | MEDIUM | 6.8 | 0.3% | Mar 11, 2026 | A vulnerability in the handling of an Egress Packet Network Interface (EPNI) Aligner interrupt in Cisco IOS XR Software ... |
| CVE-2026-20117 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow ... |
| CVE-2026-20116 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | A vulnerability in the web-based management interface of Cisco Finesse, Cisco Packaged Contact Center Enterprise (... |
| CVE-2026-1471 | MEDIUM | 6.5 | 0.2% | Mar 11, 2026 | Excessive caching of authentication context in Neo4j Enterprise edition versions prior to 2026.01.4 leads to authenticat... |
| CVE-2026-3848 | MEDIUM | 5 | 0.2% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 1... |
| CVE-2026-30234 | MEDIUM | 6.5 | 0.3% | Mar 11, 2026 | OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member w... |
| CVE-2026-29777 | MEDIUM | 6.5 | 0.3% | Mar 11, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.10, A tenant with write access to an HTTPRoute resource... |
| CVE-2026-28803 | MEDIUM | 6.5 | 0.2% | Mar 11, 2026 | Open Forms allows users create and publish smart forms. Prior to 3.3.13 and 3.4.5, to be able to cosign, the cosigner re... |
| CVE-2026-1732 | MEDIUM | 4.3 | 0.3% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, and 1... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now