2026 CVE Vulnerabilities
53,346 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34386 | HIGH | 8.8 | 0.3% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap... |
| CVE-2026-34385 | HIGH | 8.1 | 0.2% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's ... |
| CVE-2026-34375 | HIGH | 8.2 | 0.3% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirm... |
| CVE-2026-29180 | HIGH | 8.8 | 0.3% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host ... |
| CVE-2026-26061 | HIGH | 7.5 | 0.4% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoint... |
| CVE-2026-26060 | HIGH | 8.8 | 0.3% | Mar 27, 2026 | Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic c... |
| CVE-2026-4962 | HIGH | 7 | 0.2% | Mar 27, 2026 | A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in t... |
| CVE-2026-4961 | HIGH | 8.8 | 0.8% | Mar 27, 2026 | A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formQuickIndex o... |
| CVE-2026-4960 | HIGH | 8.8 | 0.8% | Mar 27, 2026 | A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/W... |
| CVE-2026-33867 | HIGH | 7.5 | 0.2% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to pass... |
| CVE-2026-33767 | HIGH | 8.8 | 0.5% | Mar 27, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like.php`, the `getLike(... |
| CVE-2026-30576 | HIGH | 7.5 | 0.3% | Mar 27, 2026 | A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file... |
| CVE-2026-30575 | HIGH | 7.5 | 0.4% | Mar 27, 2026 | A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file... |
| CVE-2026-30574 | HIGH | 7.5 | 0.3% | Mar 27, 2026 | A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file... |
| CVE-2026-4959 | HIGH | 7.5 | 0.4% | Mar 27, 2026 | A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/applica... |
| CVE-2026-32983 | HIGH | 7.5 | 0.4% | Mar 27, 2026 | Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i... |
| CVE-2026-30534 | HIGH | 8.3 | 0.3% | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via... |
| CVE-2026-30531 | HIGH | 8.8 | 0.4% | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi... |
| CVE-2026-30529 | HIGH | 8.8 | 0.4% | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi... |
| CVE-2026-5027 | HIGH | 8.8 | 31.4% | Mar 27, 2026 | The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an a... |
| CVE-2026-4984 | HIGH | 8.2 | 0.2% | Mar 27, 2026 | The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When ... |
| CVE-2026-4956 | HIGH | 7.3 | 0.3% | Mar 27, 2026 | A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. The affected element is an unknown f... |
| CVE-2026-4955 | HIGH | 7.3 | 0.3% | Mar 27, 2026 | A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. This impacts an unknown function of the... |
| CVE-2026-4953 | HIGH | 7.3 | 0.3% | Mar 27, 2026 | A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/... |
| CVE-2026-33757 | HIGH | 8.3 | 0.4% | Mar 27, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now