2026 CVE Vulnerabilities
53,332 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5177 | HIGH | 8.8 | 2.4% | Mar 31, 2026 | A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function... |
| CVE-2026-34070 | HIGH | 7.5 | 1.2% | Mar 31, 2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions i... |
| CVE-2026-34054 | HIGH | 7.8 | 0.7% | Mar 31, 2026 | vcpkg is a free and open-source C/C++ package manager. Prior to version 3.6.1#3, vcpkg's Windows builds of OpenSSL set o... |
| CVE-2026-34043 | HIGH | 7.5 | 0.5% | Mar 31, 2026 | Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, ther... |
| CVE-2026-34042 | HIGH | 8.2 | 0.5% | Mar 31, 2026 | act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache... |
| CVE-2026-34040 | HIGH | 7.8 | 8.1% | Mar 31, 2026 | Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that all... |
| CVE-2026-33997 | HIGH | 8.1 | 0.4% | Mar 31, 2026 | Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that all... |
| CVE-2026-4020 | HIGH | 7.5 | 39.7% | Mar 31, 2026 | The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2026-5115 | HIGH | 7.5 | 0.2% | Mar 31, 2026 | The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is vulnerable to session hijackin... |
| CVE-2026-30940 | HIGH | 7.2 | 1.0% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme ... |
| CVE-2026-30877 | HIGH | 7.2 | 1.5% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in t... |
| CVE-2026-21861 | HIGH | 7.2 | 2.3% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerabi... |
| CVE-2026-5156 | HIGH | 8.8 | 0.6% | Mar 31, 2026 | A vulnerability was determined in Tenda CH22 1.0.0.1. This impacts the function formQuickIndex of the file /goform/Quick... |
| CVE-2026-5155 | HIGH | 8.8 | 0.8% | Mar 30, 2026 | A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function fromAdvSetWan of the file /goform/AdvSetWan o... |
| CVE-2026-5154 | HIGH | 8.8 | 0.6% | Mar 30, 2026 | A vulnerability has been found in Tenda CH22 1.0.0.1/1.If. The impacted element is the function fromSetCfm of the file /... |
| CVE-2026-5130 | HIGH | 8.8 | 0.4% | Mar 30, 2026 | The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up... |
| CVE-2026-5153 | HIGH | 8.8 | 3.0% | Mar 30, 2026 | A flaw has been found in Tenda CH22 1.0.0.1. The affected element is the function FormWriteFacMac of the file /goform/Wr... |
| CVE-2026-33986 | HIGH | 7.5 | 0.3% | Mar 30, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in yuv_ensure_buffer() in libf... |
| CVE-2026-33985 | HIGH | 7.1 | 0.2% | Mar 30, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap ... |
| CVE-2026-33984 | HIGH | 7.5 | 0.4% | Mar 30, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libf... |
| CVE-2026-33982 | HIGH | 8.1 | 0.2% | Mar 30, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflo... |
| CVE-2026-5152 | HIGH | 8.8 | 0.7% | Mar 30, 2026 | A vulnerability was detected in Tenda CH22 1.0.0.1. Impacted is the function formCreateFileName of the file /goform/crea... |
| CVE-2026-32877 | HIGH | 8.2 | 0.3% | Mar 30, 2026 | Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that c... |
| CVE-2026-32696 | HIGH | 7.5 | 0.4% | Mar 30, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http... |
| CVE-2026-28228 | HIGH | 8.8 | 0.4% | Mar 30, 2026 | OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now