2026 CVE Vulnerabilities
53,334 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3321 | HIGH | 8.7 | 0.3% | Mar 30, 2026 | A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIME... |
| CVE-2026-28527 | HIGH | 7.3 | 0.2% | Mar 30, 2026 | BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAY... |
| CVE-2026-5121 | HIGH | 7.5 | 1.1% | Mar 30, 2026 | A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer ... |
| CVE-2026-4416 | HIGH | 8.5 | 0.2% | Mar 30, 2026 | The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticate... |
| CVE-2026-3945 | HIGH | 8.7 | 0.6% | Mar 30, 2026 | An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version ... |
| CVE-2026-2328 | HIGH | 7.5 | 0.3% | Mar 30, 2026 | An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their i... |
| CVE-2026-5119 | HIGH | 8.2 | 0.3% | Mar 30, 2026 | A flaw was found in libsoup. When establishing HTTPS tunnels through a configured HTTP proxy, sensitive session cookies ... |
| CVE-2026-5105 | HIGH | 8.8 | 3.7% | Mar 30, 2026 | A vulnerability was detected in Totolink A3300R 17.0.0cu.557_b20221024. The affected element is the function setVpnPassC... |
| CVE-2026-5104 | HIGH | 8.8 | 2.5% | Mar 30, 2026 | A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Impacted is the function setStatic... |
| CVE-2026-5103 | HIGH | 8.8 | 3.6% | Mar 30, 2026 | A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. This issue affects the function setUPnPCfg of ... |
| CVE-2026-3124 | HIGH | 7.5 | 0.3% | Mar 30, 2026 | The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i... |
| CVE-2026-5102 | HIGH | 8.8 | 2.2% | Mar 30, 2026 | A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. This vulnerability affects the function s... |
| CVE-2026-2370 | HIGH | 8.8 | 0.4% | Mar 30, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18.9 before 18.9.3, and 1... |
| CVE-2026-5101 | HIGH | 8.8 | 2.2% | Mar 29, 2026 | A vulnerability was identified in Totolink A3300R 17.0.0cu.557_b20221024. This affects the function setLanCfg of the fil... |
| CVE-2026-4946 | HIGH | 8.8 | 0.4% | Mar 29, 2026 | Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data... |
| CVE-2026-0562 | HIGH | 8.3 | 0.3% | Mar 29, 2026 | A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or rej... |
| CVE-2026-0560 | HIGH | 7.5 | 1.8% | Mar 29, 2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in th... |
| CVE-2026-34005 | HIGH | 8.8 | 1.5% | Mar 29, 2026 | In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via s... |
| CVE-2026-5046 | HIGH | 8.8 | 0.6% | Mar 29, 2026 | A flaw has been found in Tenda FH1201 1.2.0.14(408). Affected is the function formWrlExtraSet of the file /goform/WrlExt... |
| CVE-2026-5045 | HIGH | 8.8 | 0.7% | Mar 29, 2026 | A vulnerability was detected in Tenda FH1201 1.2.0.14(408). This impacts the function WrlclientSet of the file /goform/W... |
| CVE-2026-5044 | HIGH | 8.8 | 0.7% | Mar 29, 2026 | A security vulnerability has been detected in Belkin F9K1122 1.00.33. This affects the function formSetSystemSettings of... |
| CVE-2026-33575 | HIGH | 8.6 | 0.2% | Mar 29, 2026 | OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pai... |
| CVE-2026-33573 | HIGH | 8.8 | 0.3% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authentica... |
| CVE-2026-32980 | HIGH | 8.7 | 0.5% | Mar 29, 2026 | OpenClaw before 2026.3.13 reads and buffers Telegram webhook request bodies before validating the x-telegram-bot-api-sec... |
| CVE-2026-32978 | HIGH | 7.5 | 0.2% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable f... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now