2026 CVE Vulnerabilities
53,348 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4953 | HIGH | 7.3 | 0.3% | Mar 27, 2026 | A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/... |
| CVE-2026-33757 | HIGH | 8.3 | 0.4% | Mar 27, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for ... |
| CVE-2026-33755 | HIGH | 8.8 | 0.4% | Mar 27, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, a... |
| CVE-2026-33750 | HIGH | 7.5 | 0.4% | Mar 27, 2026 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, ... |
| CVE-2026-33748 | HIGH | 7.5 | 0.5% | Mar 27, 2026 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P... |
| CVE-2026-33433 | HIGH | 8.8 | 0.5% | Mar 27, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.3, when `headerField... |
| CVE-2026-30637 | HIGH | 7.5 | 0.5% | Mar 27, 2026 | Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and b... |
| CVE-2026-29871 | HIGH | 7.5 | 0.6% | Mar 27, 2026 | A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251... |
| CVE-2026-27880 | HIGH | 7.5 | 0.8% | Mar 27, 2026 | The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory cra... |
| CVE-2026-27877 | HIGH | 7.5 | 0.3% | Mar 27, 2026 | When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being u... |
| CVE-2026-32695 | HIGH | 7.7 | 0.5% | Mar 27, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik's Knative provider ... |
| CVE-2026-4982 | HIGH | 7.3 | 0.2% | Mar 27, 2026 | A user with permission "update world" in any Venueless world is able to exfiltrate chat messages from direct messages or... |
| CVE-2026-25099 | HIGH | 8.8 | 1.9% | Mar 27, 2026 | Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension wi... |
| CVE-2026-27858 | HIGH | 7.5 | 0.8% | Mar 27, 2026 | Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount ... |
| CVE-2026-27857 | HIGH | 7.5 | 0.7% | Mar 27, 2026 | Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands wi... |
| CVE-2026-24031 | HIGH | 8.2 | 0.4% | Mar 27, 2026 | Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows... |
| CVE-2026-32678 | HIGH | 8.7 | 0.3% | Mar 27, 2026 | Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical confi... |
| CVE-2026-22744 | HIGH | 7.5 | 0.3% | Mar 27, 2026 | In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value fo... |
| CVE-2026-22743 | HIGH | 7.5 | 0.3% | Mar 27, 2026 | Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. Whe... |
| CVE-2026-22742 | HIGH | 8.6 | 0.4% | Mar 27, 2026 | Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatMo... |
| CVE-2026-4910 | HIGH | 7.3 | 0.3% | Mar 27, 2026 | A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus up to 1.3.44. Affected is an u... |
| CVE-2026-4906 | HIGH | 8.8 | 2.6% | Mar 27, 2026 | A vulnerability was determined in Tenda AC5 15.03.06.47. The affected element is the function decodePwd of the file /gof... |
| CVE-2026-33935 | HIGH | 7.5 | 0.5% | Mar 27, 2026 | MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated att... |
| CVE-2026-33745 | HIGH | 7.4 | 0.3% | Mar 27, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP ... |
| CVE-2026-33744 | HIGH | 7.8 | 0.3% | Mar 27, 2026 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now