2026 CVE Vulnerabilities
53,348 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33735 | HIGH | 8.8 | 0.4% | Mar 27, 2026 | MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypas... |
| CVE-2026-33725 | HIGH | 7.2 | 0.8% | Mar 27, 2026 | Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1... |
| CVE-2026-33721 | HIGH | 7.5 | 0.9% | Mar 27, 2026 | MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a h... |
| CVE-2026-33699 | HIGH | 7.5 | 0.5% | Mar 27, 2026 | pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attack... |
| CVE-2026-4905 | HIGH | 8.8 | 0.6% | Mar 27, 2026 | A vulnerability was found in Tenda AC5 15.03.06.47. Impacted is the function formWifiWpsOOB of the file /goform/WifiWpsO... |
| CVE-2026-4904 | HIGH | 8.8 | 0.7% | Mar 27, 2026 | A vulnerability has been found in Tenda AC5 15.03.06.47. This issue affects the function formSetCfm of the file /goform/... |
| CVE-2026-33898 | HIGH | 8.8 | 0.3% | Mar 27, 2026 | Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui... |
| CVE-2026-29070 | HIGH | 8.1 | 0.3% | Mar 27, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.... |
| CVE-2026-28788 | HIGH | 7.1 | 2.9% | Mar 27, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.... |
| CVE-2026-27893 | HIGH | 8.8 | 1.4% | Mar 27, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to versio... |
| CVE-2026-4903 | HIGH | 8.8 | 5.5% | Mar 26, 2026 | A flaw has been found in Tenda AC5 15.03.06.47. This vulnerability affects the function formQuickIndex of the file /gofo... |
| CVE-2026-4902 | HIGH | 8.8 | 0.6% | Mar 26, 2026 | A vulnerability was detected in Tenda AC5 15.03.06.47. This affects the function fromAddressNat of the file /goform/addr... |
| CVE-2026-33711 | HIGH | 7.8 | 0.4% | Mar 26, 2026 | Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API reli... |
| CVE-2026-3650 | HIGH | 8.7 | 0.4% | Mar 26, 2026 | A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-... |
| CVE-2026-33687 | HIGH | 8.8 | 0.5% | Mar 26, 2026 | Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability... |
| CVE-2026-33686 | HIGH | 8.8 | 0.5% | Mar 26, 2026 | Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal v... |
| CVE-2026-33671 | HIGH | 7.5 | 0.4% | Mar 26, 2026 | Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expr... |
| CVE-2026-33670 | HIGH | 7.5 | 0.7% | Mar 26, 2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to tr... |
| CVE-2026-33669 | HIGH | 7.5 | 0.5% | Mar 26, 2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/... |
| CVE-2026-33661 | HIGH | 7.5 | 0.5% | Mar 26, 2026 | Pay is an open-source payment SDK extension package for various Chinese payment services. Prior to version 3.7.20, the `... |
| CVE-2026-28377 | HIGH | 7.5 | 0.2% | Mar 26, 2026 | A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, p... |
| CVE-2026-4933 | HIGH | 7.5 | 0.2% | Mar 26, 2026 | Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects... |
| CVE-2026-3622 | HIGH | 7.5 | 0.4% | Mar 26, 2026 | The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-boun... |
| CVE-2026-3573 | HIGH | 7.5 | 0.2% | Mar 26, 2026 | Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Resource Injection.This issue affect... |
| CVE-2026-33645 | HIGH | 8.1 | 0.4% | Mar 26, 2026 | Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerabilit... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now