2026 CVE Vulnerabilities
52,233 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25571 | MEDIUM | 5.5 | 0.1% | Mar 10, 2026 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK client component doe... |
| CVE-2026-25186 | MEDIUM | 5.5 | 0.6% | Mar 10, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Accessibility Infrastructure (ATBroker.exe) allows... |
| CVE-2026-25185 | MEDIUM | 5.3 | 0.9% | Mar 10, 2026 | Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attac... |
| CVE-2026-25180 | MEDIUM | 5.5 | 0.7% | Mar 10, 2026 | Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. |
| CVE-2026-25169 | MEDIUM | 5.5 | 0.5% | Mar 10, 2026 | Divide by zero in Microsoft Graphics Component allows an unauthorized attacker to deny service locally. |
| CVE-2026-25168 | MEDIUM | 5.5 | 0.5% | Mar 10, 2026 | Null pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to deny service locally. |
| CVE-2026-24641 | MEDIUM | 6.5 | 0.4% | Mar 10, 2026 | A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.... |
| CVE-2026-24640 | MEDIUM | 6.6 | 0.6% | Mar 10, 2026 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7... |
| CVE-2026-24297 | MEDIUM | 4.8 | 0.3% | Mar 10, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows a... |
| CVE-2026-24288 | MEDIUM | 6.8 | 0.4% | Mar 10, 2026 | Heap-based buffer overflow in Windows Mobile Broadband allows an unauthorized attacker to execute code with a physical a... |
| CVE-2026-24282 | MEDIUM | 5.5 | 0.4% | Mar 10, 2026 | Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. |
| CVE-2026-23907 | MEDIUM | 5.3 | 0.9% | Mar 10, 2026 | This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.... |
| CVE-2026-23656 | MEDIUM | 5.9 | 0.3% | Mar 10, 2026 | Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoof... |
| CVE-2026-22628 | MEDIUM | 6.7 | 0.1% | Mar 10, 2026 | An improper access control vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an authenticated a... |
| CVE-2026-22614 | MEDIUM | 6.1 | 0.1% | Mar 10, 2026 | The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an a... |
| CVE-2026-1286 | MEDIUM | 6.5 | 0.3% | Mar 10, 2026 | CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity an... |
| CVE-2026-30927 | MEDIUM | 5.4 | 0.3% | Mar 10, 2026 | Admidio is an open-source user management solution. Prior to 5.0.6, in modules/events/events_function.php, the event par... |
| CVE-2026-30919 | MEDIUM | 5.4 | 0.2% | Mar 10, 2026 | facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as... |
| CVE-2026-30918 | MEDIUM | 6.1 | 0.2% | Mar 10, 2026 | facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs wh... |
| CVE-2026-30913 | MEDIUM | 4.6 | 0.2% | Mar 10, 2026 | Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their ni... |
| CVE-2026-30885 | MEDIUM | 5.3 | 0.4% | Mar 10, 2026 | WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns al... |
| CVE-2026-30870 | MEDIUM | 6.5 | 0.2% | Mar 10, 2026 | PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync stre... |
| CVE-2026-29773 | MEDIUM | 4.3 | 0.2% | Mar 10, 2026 | Kubewarden is a policy engine for Kubernetes. Kubewarden cluster operators can grant permissions to users to deploy name... |
| CVE-2026-28512 | MEDIUM | 6.1 | 0.2% | Mar 10, 2026 | Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to befo... |
| CVE-2026-28267 | MEDIUM | 6.8 | 0.1% | Mar 10, 2026 | Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwrit... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now