2026 CVE Vulnerabilities
53,332 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27599 | HIGH | 7.2 | 0.4% | Mar 30, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-27018 | HIGH | 7.5 | 0.5% | Mar 30, 2026 | Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can ... |
| CVE-2026-25627 | HIGH | 7.5 | 0.5% | Mar 30, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSoc... |
| CVE-2026-5150 | HIGH | 7.3 | 0.3% | Mar 30, 2026 | A security vulnerability has been detected in code-projects Accounting System 1.0. This issue affects some unknown proce... |
| CVE-2026-31831 | HIGH | 7.5 | 0.5% | Mar 30, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/... |
| CVE-2026-21710 | HIGH | 7.5 | 26.4% | Mar 30, 2026 | A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `_... |
| CVE-2026-5147 | HIGH | 7.3 | 0.3% | Mar 30, 2026 | A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This affects an unknown part of the file /admin... |
| CVE-2026-3991 | HIGH | 7.8 | 0.2% | Mar 30, 2026 | Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 M... |
| CVE-2026-3502 | HIGH | 7.8 | 5.8% | Mar 30, 2026 | TrueConf Client downloads application update code and applies it without performing verification. An attacker who is abl... |
| CVE-2026-34714 | HIGH | 8.6 | 0.6% | Mar 30, 2026 | Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configurat... |
| CVE-2026-29925 | HIGH | 7.7 | 0.3% | Mar 30, 2026 | Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php. |
| CVE-2026-29924 | HIGH | 7.6 | 0.3% | Mar 30, 2026 | Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the a... |
| CVE-2026-4046 | HIGH | 7.5 | 0.4% | Mar 30, 2026 | The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when convertin... |
| CVE-2026-33028 | HIGH | 7.5 | 0.5% | Mar 30, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerabl... |
| CVE-2026-30077 | HIGH | 7.5 | 0.3% | Mar 30, 2026 | OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But ... |
| CVE-2026-29872 | HIGH | 8.2 | 0.3% | Mar 30, 2026 | A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80... |
| CVE-2026-29954 | HIGH | 7.6 | 0.3% | Mar 30, 2026 | In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing th... |
| CVE-2026-34472 | HIGH | 7.1 | 8.9% | Mar 30, 2026 | Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows u... |
| CVE-2026-33643 | HIGH | 7.4 | 0.2% | Mar 30, 2026 | SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the mysqlColumnAsInsert function in file pl... |
| CVE-2026-2285 | HIGH | 7.5 | 0.6% | Mar 30, 2026 | CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validati... |
| CVE-2026-29953 | HIGH | 7.4 | 0.2% | Mar 30, 2026 | SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the columnAsInsert function in file plugins... |
| CVE-2026-5165 | HIGH | 7.8 | 0.1% | Mar 30, 2026 | A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it... |
| CVE-2026-33373 | HIGH | 8.8 | 0.2% | Mar 30, 2026 | An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability e... |
| CVE-2026-3321 | HIGH | 8.7 | 0.3% | Mar 30, 2026 | A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIME... |
| CVE-2026-28527 | HIGH | 7.3 | 0.2% | Mar 30, 2026 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAY... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now