2026 CVE Vulnerabilities
53,393 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32948 | HIGH | 7.8 | 0.3% | Mar 24, 2026 | sbt is a build tool for Scala, Java, and others. From version 0.9.5 to before version 1.12.7, on Windows, sbt uses Proce... |
| CVE-2026-22559 | HIGH | 8.8 | 0.3% | Mar 24, 2026 | An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the ac... |
| CVE-2026-33539 | HIGH | 7.2 | 0.5% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33538 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33508 | HIGH | 7.5 | 0.3% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33498 | HIGH | 7.5 | 0.5% | Mar 24, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-33417 | HIGH | 7.1 | 0.3% | Mar 24, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in ... |
| CVE-2026-30932 | HIGH | 8.8 | 0.5% | Mar 24, 2026 | Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessi... |
| CVE-2026-29772 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full reque... |
| CVE-2026-23921 | HIGH | 8.7 | 0.2% | Mar 24, 2026 | A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiS... |
| CVE-2026-23920 | HIGH | 7.7 | 0.2% | Mar 24, 2026 | Host and event action script input is validated with a regex (set by the administrator), but the validation runs in mult... |
| CVE-2026-23919 | HIGH | 7.1 | 0.2% | Mar 24, 2026 | For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript repro... |
| CVE-2026-1995 | HIGH | 7.8 | 0.2% | Mar 24, 2026 | In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from seve... |
| CVE-2026-33399 | HIGH | 7.7 | 0.3% | Mar 24, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in v... |
| CVE-2026-33157 | HIGH | 7.2 | 1.0% | Mar 24, 2026 | Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RC... |
| CVE-2026-32854 | HIGH | 7.5 | 5.3% | Mar 24, 2026 | LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the... |
| CVE-2026-32853 | HIGH | 8.1 | 0.4% | Mar 24, 2026 | LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability in the ... |
| CVE-2026-33679 | HIGH | 7.4 | 0.3% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in ... |
| CVE-2026-33678 | HIGH | 8.1 | 0.3% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, `TaskAttachment.ReadOne()` queri... |
| CVE-2026-33668 | HIGH | 8.1 | 0.5% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, w... |
| CVE-2026-33336 | HIGH | 8.8 | 1.1% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, t... |
| CVE-2026-33335 | HIGH | 8 | 0.2% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, t... |
| CVE-2026-29839 | HIGH | 8.8 | 0.1% | Mar 24, 2026 | DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php. |
| CVE-2026-4775 | HIGH | 7.8 | 0.6% | Mar 24, 2026 | A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the ... |
| CVE-2026-33554 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Manag... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now