2026 CVE Vulnerabilities
53,398 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3533 | HIGH | 8.8 | 0.7% | Mar 24, 2026 | The Jupiter X Core plugin for WordPress is vulnerable to limited file uploads due to missing authorization on import_pop... |
| CVE-2026-33283 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing malformed UL NAS Tra... |
| CVE-2026-33282 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing a malformed NGAP Loc... |
| CVE-2026-33281 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Ella Core is a 5G core designed for private networks. Versions prior to 1.6.0 panic when processing NGAP messages with i... |
| CVE-2026-33250 | HIGH | 7.5 | 0.8% | Mar 24, 2026 | Freeciv21 is a free open source, turn-based, empire-building strategy game. Versions prior to 3.1.1 crash with a stack o... |
| CVE-2026-33242 | HIGH | 7.5 | 0.6% | Mar 24, 2026 | Salvo is a Rust web framework. Versions 0.39.0 through 0.89.2 have a Path Traversal and Access Control Bypass vulnerabil... |
| CVE-2026-33241 | HIGH | 7.5 | 0.4% | Mar 24, 2026 | Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method ... |
| CVE-2026-33176 | HIGH | 7.5 | 0.6% | Mar 24, 2026 | Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to v... |
| CVE-2026-33174 | HIGH | 7.5 | 0.6% | Mar 24, 2026 | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, a... |
| CVE-2026-4306 | HIGH | 7.5 | 0.4% | Mar 23, 2026 | The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up to, ... |
| CVE-2026-33046 | HIGH | 8.8 | 0.8% | Mar 23, 2026 | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In vers... |
| CVE-2026-4612 | HIGH | 7.3 | 0.3% | Mar 23, 2026 | A vulnerability has been found in itsourcecode Free Hotel Reservation System 1.0. This affects an unknown part of the fi... |
| CVE-2026-4611 | HIGH | 8.8 | 3.0% | Mar 23, 2026 | A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the fu... |
| CVE-2026-33634 | HIGH | 8.8 | 60.4% | Mar 23, 2026 | Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy... |
| CVE-2026-32300 | HIGH | 8.1 | 0.3% | Mar 23, 2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the... |
| CVE-2026-32299 | HIGH | 7.5 | 0.3% | Mar 23, 2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the... |
| CVE-2026-32277 | HIGH | 8.7 | 0.3% | Mar 23, 2026 | Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cro... |
| CVE-2026-32276 | HIGH | 8.8 | 0.5% | Mar 23, 2026 | Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the... |
| CVE-2026-1940 | HIGH | 7.5 | 0.2% | Mar 23, 2026 | An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added... |
| CVE-2026-4368 | HIGH | 7.7 | 3.6% | Mar 23, 2026 | Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN,... |
| CVE-2026-23882 | HIGH | 7.2 | 0.4% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creati... |
| CVE-2026-23482 | HIGH | 7.5 | 1.5% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the file server endpoint does not perform perm... |
| CVE-2026-23480 | HIGH | 8.8 | 0.3% | Mar 23, 2026 | Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is a privilege escalation vulnerability.... |
| CVE-2026-33719 | HIGH | 8.6 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN... |
| CVE-2026-33717 | HIGH | 8.8 | 0.4% | Mar 23, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()`... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now