2026 CVE Vulnerabilities
53,393 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33316 | HIGH | 8.1 | 0.4% | Mar 24, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password res... |
| CVE-2026-32647 | HIGH | 8.5 | 0.9% | Mar 24, 2026 | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker t... |
| CVE-2026-30653 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | An issue in Free5GC v.4.2.0 and before allows a remote attacker to cause a denial of service via the function HandleAuth... |
| CVE-2026-27784 | HIGH | 8.5 | 1.0% | Mar 24, 2026 | The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow ... |
| CVE-2026-27654 | HIGH | 8.8 | 21.6% | Mar 24, 2026 | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to ... |
| CVE-2026-27651 | HIGH | 8.7 | 0.9% | Mar 24, 2026 | When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause ... |
| CVE-2026-33497 | HIGH | 7.5 | 8.0% | Mar 24, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_p... |
| CVE-2026-33484 | HIGH | 7.5 | 5.8% | Mar 24, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/ap... |
| CVE-2026-33418 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | DiceBear is an avatar library for designers and developers. Prior to version 9.4.2, the `ensureSize()` function in `@dic... |
| CVE-2026-33310 | HIGH | 8.8 | 0.4% | Mar 24, 2026 | Intake is a package for finding, investigating, loading and disseminating data. Prior to version 2.0.9, the shell() synt... |
| CVE-2026-4727 | HIGH | 7.5 | 0.5% | Mar 24, 2026 | Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
| CVE-2026-4726 | HIGH | 7.5 | 0.5% | Mar 24, 2026 | Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
| CVE-2026-4722 | HIGH | 8.8 | 0.3% | Mar 24, 2026 | Privilege escalation in the IPC component. This vulnerability was fixed in Firefox 149 and Thunderbird 149. |
| CVE-2026-4719 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 149, Firefox ESR ... |
| CVE-2026-4718 | HIGH | 8.1 | 0.3% | Mar 24, 2026 | Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, T... |
| CVE-2026-4714 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140... |
| CVE-2026-4713 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9,... |
| CVE-2026-4712 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Information disclosure in the Widget: Cocoa component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, T... |
| CVE-2026-4709 | HIGH | 7.5 | 0.5% | Mar 24, 2026 | Incorrect boundary conditions in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 149, Firefox ES... |
| CVE-2026-4708 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9,... |
| CVE-2026-4707 | HIGH | 7.5 | 0.6% | Mar 24, 2026 | Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ... |
| CVE-2026-4706 | HIGH | 7.5 | 0.5% | Mar 24, 2026 | Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ... |
| CVE-2026-4704 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Denial-of-service in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Th... |
| CVE-2026-4699 | HIGH | 7.5 | 0.7% | Mar 24, 2026 | Incorrect boundary conditions in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 149, Fire... |
| CVE-2026-4697 | HIGH | 7.5 | 0.7% | Mar 24, 2026 | Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 149, Fir... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now