2026 CVE Vulnerabilities
52,233 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3848 | MEDIUM | 5 | 0.2% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 1... |
| CVE-2026-30234 | MEDIUM | 6.5 | 0.3% | Mar 11, 2026 | OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member w... |
| CVE-2026-29777 | MEDIUM | 6.5 | 0.3% | Mar 11, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.10, A tenant with write access to an HTTPRoute resource... |
| CVE-2026-28803 | MEDIUM | 6.5 | 0.2% | Mar 11, 2026 | Open Forms allows users create and publish smart forms. Prior to 3.3.13 and 3.4.5, to be able to cosign, the cosigner re... |
| CVE-2026-1732 | MEDIUM | 4.3 | 0.3% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.6 before 18.7.6, 18.8 before 18.8.6, and 1... |
| CVE-2026-1663 | MEDIUM | 4.3 | 0.2% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, and 1... |
| CVE-2026-1230 | MEDIUM | 6.5 | 0.2% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18... |
| CVE-2026-1090 | MEDIUM | 5.4 | 0.2% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 1... |
| CVE-2026-0602 | MEDIUM | 4.3 | 0.2% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 1... |
| CVE-2026-32229 | MEDIUM | 6.8 | 0.2% | Mar 11, 2026 | In JetBrains Hub before 2026.1 possible on sign-in account mismatch with non-SSO auth and 2FA disabled |
| CVE-2026-3904 | MEDIUM | 6.2 | 0.1% | Mar 11, 2026 | Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library ... |
| CVE-2026-32061 | MEDIUM | 6.7 | 0.1% | Mar 11, 2026 | OpenClaw versions prior to 2026.2.17 contain a path traversal vulnerability in the $include directive resolution that al... |
| CVE-2026-3784 | MEDIUM | 6.5 | 0.3% | Mar 11, 2026 | curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses diffe... |
| CVE-2026-3783 | MEDIUM | 5.3 | 0.3% | Mar 11, 2026 | When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl... |
| CVE-2026-1965 | MEDIUM | 6.5 | 0.3% | Mar 11, 2026 | libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS r... |
| CVE-2026-3906 | MEDIUM | 4.3 | 0.3% | Mar 11, 2026 | WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collab... |
| CVE-2026-3492 | MEDIUM | 6.4 | 0.2% | Mar 11, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including... |
| CVE-2026-3903 | MEDIUM | 4.3 | 0.1% | Mar 11, 2026 | The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Cross-Site Request F... |
| CVE-2026-2918 | MEDIUM | 6.4 | 0.2% | Mar 11, 2026 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up... |
| CVE-2026-2917 | MEDIUM | 5.4 | 0.2% | Mar 11, 2026 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up... |
| CVE-2026-3825 | MEDIUM | 6.1 | 0.3% | Mar 11, 2026 | IFTOP developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attacker... |
| CVE-2026-3824 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL... |
| CVE-2026-3534 | MEDIUM | 6.4 | 0.2% | Mar 11, 2026 | The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-c... |
| CVE-2026-3884 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that a... |
| CVE-2026-2707 | MEDIUM | 6.4 | 0.2% | Mar 11, 2026 | The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API entry submission endpoint... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now