2026 CVE Vulnerabilities
53,133 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2606 | MEDIUM | 6.5 | 0.3% | Mar 3, 2026 | IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API M... |
| CVE-2026-1265 | MEDIUM | 5.3 | 0.2% | Mar 3, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log f... |
| CVE-2026-0540 | MEDIUM | 6.1 | 0.3% | Mar 3, 2026 | DOMPurify 3.1.3 through 3.3.1 and 2.5.3 through 2.5.8, fixed in commit 2726c74, contain a cross-site scripting vulnerabi... |
| CVE-2026-3344 | MEDIUM | 4.9 | 0.3% | Mar 3, 2026 | A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and... |
| CVE-2026-3343 | MEDIUM | 6.1 | 0.2% | Mar 3, 2026 | A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript... |
| CVE-2026-3351 | MEDIUM | 4.3 | 0.1% | Mar 3, 2026 | Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, ... |
| CVE-2026-3455 | MEDIUM | 6.1 | 0.3% | Mar 3, 2026 | Versions of the package mailparser before 3.9.3 are vulnerable to Cross-site Scripting (XSS) via the textToHtml() functi... |
| CVE-2026-20801 | MEDIUM | 5.6 | 0.1% | Mar 3, 2026 | Cleartext Transmission of Sensitive Information (CWE-319) in a component used in the Gallagher Hanwha VMS and Gallagher ... |
| CVE-2026-1487 | MEDIUM | 6.5 | 0.3% | Mar 3, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to SQL Injection ... |
| CVE-2026-1336 | MEDIUM | 5.3 | 0.3% | Mar 3, 2026 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and m... |
| CVE-2026-2583 | MEDIUM | 6.4 | 0.2% | Mar 2, 2026 | The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in a... |
| CVE-2026-2256 | MEDIUM | 6.5 | 1.6% | Mar 2, 2026 | A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker t... |
| CVE-2026-27631 | MEDIUM | 5.3 | 0.3% | Mar 2, 2026 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada... |
| CVE-2026-25477 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redire... |
| CVE-2026-0027 | MEDIUM | 6.7 | 0.1% | Mar 2, 2026 | In smmu_detach_dev of arm-smmu-v3.c, there is a possible out of bounds write due to a use after free. This could lead to... |
| CVE-2026-0024 | MEDIUM | 4 | 0.1% | Mar 2, 2026 | In isRedactionNeededForOpenViaContentResolver of MediaProvider.java, there is a possible way to reveal the location of m... |
| CVE-2026-0015 | MEDIUM | 6.2 | 0.1% | Mar 2, 2026 | In multiple locations of AppOpsService.java, there is a possible persistent denial of service due to improper input vali... |
| CVE-2026-0014 | MEDIUM | 6.2 | 0.1% | Mar 2, 2026 | In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input v... |
| CVE-2026-0012 | MEDIUM | 6.2 | 0.1% | Mar 2, 2026 | In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in... |
| CVE-2026-0005 | MEDIUM | 6.2 | 0.1% | Mar 2, 2026 | In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing lim... |
| CVE-2026-28401 | MEDIUM | 5.4 | 0.2% | Mar 2, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, rich text cell content rendered via... |
| CVE-2026-28398 | MEDIUM | 5.4 | 0.1% | Mar 2, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, user-controlled content in comments... |
| CVE-2026-28397 | MEDIUM | 5.4 | 0.2% | Mar 2, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, comments rendered via v-html withou... |
| CVE-2026-28396 | MEDIUM | 6.5 | 0.2% | Mar 2, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password reset flow did not rev... |
| CVE-2026-28361 | MEDIUM | 6.3 | 0.2% | Mar 2, 2026 | NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the MCP token service did not valid... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now