2026 CVE Vulnerabilities
52,233 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27223 | MEDIUM | 5.4 | 0.2% | Mar 11, 2026 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2026-2569 | MEDIUM | 6.4 | 0.2% | Mar 11, 2026 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2026-27270 | MEDIUM | 5.5 | 0.1% | Mar 10, 2026 | Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to mem... |
| CVE-2026-27268 | MEDIUM | 5.5 | 0.1% | Mar 10, 2026 | Illustrator versions 29.8.4, 30.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to mem... |
| CVE-2026-31838 | MEDIUM | 5.3 | 0.2% | Mar 10, 2026 | Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a vulnerabi... |
| CVE-2026-31833 | MEDIUM | 6.7 | 0.3% | Mar 10, 2026 | Umbraco is an ASP.NET CMS. From 16.2.0 to before 16.5.1 and 17.2.2, An authenticated backoffice user with access to Sett... |
| CVE-2026-31832 | MEDIUM | 5.4 | 0.2% | Mar 10, 2026 | Umbraco is an ASP.NET CMS. From 14.0.0 to before 16.5.1 and 17.2.2, A broken object-level authorization vulnerability ex... |
| CVE-2026-31826 | MEDIUM | 5.5 | 0.2% | Mar 10, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.8.0, an attacker who uses this vulnerability can cra... |
| CVE-2026-31825 | MEDIUM | 5.3 | 0.2% | Mar 10, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. Sylius API filters ProductPriceOrderFilter and TranslationOrder... |
| CVE-2026-31824 | MEDIUM | 5.9 | 0.2% | Mar 10, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. A Time-of-Check To Time-of-Use (TOCTOU) race condition was disc... |
| CVE-2026-31823 | MEDIUM | 4.8 | 0.1% | Mar 10, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. An authenticated stored cross-site scripting (XSS) vulnerabilit... |
| CVE-2026-31822 | MEDIUM | 6.1 | 0.2% | Mar 10, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. A cross-site scripting (XSS) vulnerability exists in the shop c... |
| CVE-2026-31821 | MEDIUM | 5.3 | 0.2% | Mar 10, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. The POST /api/v2/shop/orders/{tokenValue}/items endpoint does n... |
| CVE-2026-31820 | MEDIUM | 6.5 | 0.3% | Mar 10, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulner... |
| CVE-2026-31819 | MEDIUM | 6.1 | 0.2% | Mar 10, 2026 | Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserContro... |
| CVE-2026-31815 | MEDIUM | 5.3 | 0.2% | Mar 10, 2026 | Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipula... |
| CVE-2026-31812 | MEDIUM | 5.3 | 0.5% | Mar 10, 2026 | Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, u... |
| CVE-2026-27221 | MEDIUM | 5.5 | 0.1% | Mar 10, 2026 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Val... |
| CVE-2026-31809 | MEDIUM | 6.1 | 0.5% | Mar 10, 2026 | SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) checks href attr... |
| CVE-2026-31808 | MEDIUM | 5.3 | 0.3% | Mar 10, 2026 | file-type detects the file type of a file, stream, or data. Prior to 21.3.1, a denial of service vulnerability exists in... |
| CVE-2026-31807 | MEDIUM | 6.1 | 0.4% | Mar 10, 2026 | SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) blocks dangerous... |
| CVE-2026-30962 | MEDIUM | 6.5 | 0.3% | Mar 10, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a... |
| CVE-2026-30954 | MEDIUM | 4.3 | 0.2% | Mar 10, 2026 | LinkAce is a self-hosted archive to collect website links. In 2.1.0 and earlier, the processTaxonomy() method in LinkRep... |
| CVE-2026-30953 | MEDIUM | 6.5 | 0.2% | Mar 10, 2026 | LinkAce is a self-hosted archive to collect website links. When a user creates a link via POST /links, the server fetche... |
| CVE-2026-30948 | MEDIUM | 5.4 | 0.2% | Mar 10, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now