2026 CVE Vulnerabilities
53,349 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32857 | HIGH | 8.6 | 0.4% | Mar 26, 2026 | Firecrawl version 2.8.0 and prior contain a server-side request forgery (SSRF) protection bypass vulnerability in the Pl... |
| CVE-2026-4867 | HIGH | 7.5 | 0.5% | Mar 26, 2026 | Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separ... |
| CVE-2026-3108 | HIGH | 8.8 | 0.3% | Mar 26, 2026 | Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-cont... |
| CVE-2026-33636 | HIGH | 7.6 | 0.6% | Mar 26, 2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2026-33468 | HIGH | 8.1 | 0.4% | Mar 26, 2026 | Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeStr... |
| CVE-2026-33442 | HIGH | 8.1 | 0.4% | Mar 26, 2026 | Kysely is a type-safe TypeScript SQL query builder. In versions 0.28.12 and 0.28.13, the `sanitizeStringLiteral` method ... |
| CVE-2026-33430 | HIGH | 7.3 | 0.1% | Mar 26, 2026 | Briefcase is a tool for converting a Python project into a standalone native application. Starting in version 0.3.0 and ... |
| CVE-2026-33416 | HIGH | 7.5 | 1.1% | Mar 26, 2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2026-32846 | HIGH | 7.5 | 0.7% | Mar 26, 2026 | OpenClaw before 2026.3.28 contains a path traversal vulnerability in media parsing that allows attackers to read arbitra... |
| CVE-2026-27828 | HIGH | 7.5 | 0.3% | Mar 26, 2026 | EVerest is an EV charging software stack. Prior to version 2026.02.0, ISO15118_chargerImpl::handle_session_setup uses v2... |
| CVE-2026-26074 | HIGH | 7 | 0.1% | Mar 26, 2026 | EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::map<std... |
| CVE-2026-28298 | HIGH | 8.1 | 0.3% | Mar 26, 2026 | SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when... |
| CVE-2026-28297 | HIGH | 8.7 | 0.4% | Mar 26, 2026 | SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when... |
| CVE-2026-27664 | HIGH | 8.7 | 0.4% | Mar 26, 2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base syst... |
| CVE-2026-27663 | HIGH | 7.1 | 0.3% | Mar 26, 2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base ... |
| CVE-2026-26008 | HIGH | 7.5 | 0.4% | Mar 26, 2026 | EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that le... |
| CVE-2026-23995 | HIGH | 7.8 | 0.2% | Mar 26, 2026 | EVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface initi... |
| CVE-2026-22790 | HIGH | 8.8 | 0.5% | Mar 26, 2026 | EVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len` afte... |
| CVE-2026-22593 | HIGH | 7.8 | 0.1% | Mar 26, 2026 | EVerest is an EV charging software stack. Prior to version 2026.02.0, an off-by-one check in IsoMux certificate filename... |
| CVE-2026-33413 | HIGH | 8.8 | 0.2% | Mar 26, 2026 | etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9,... |
| CVE-2026-2511 | HIGH | 7.5 | 0.3% | Mar 26, 2026 | The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `mu... |
| CVE-2026-2231 | HIGH | 7.2 | 0.3% | Mar 26, 2026 | The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all vers... |
| CVE-2026-4887 | HIGH | 7.1 | 0.6% | Mar 26, 2026 | A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A re... |
| CVE-2026-1961 | HIGH | 8 | 1.4% | Mar 26, 2026 | A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket pr... |
| CVE-2026-24068 | HIGH | 8.8 | 0.4% | Mar 26, 2026 | The VSL privileged helper does utilize NSXPC for IPC. The implementation of the "shouldAcceptNewConnection" function, wh... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now