2026 CVE Vulnerabilities
53,457 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32622 | HIGH | 8.8 | 0.6% | Mar 19, 2026 | SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a S... |
| CVE-2026-26139 | HIGH | 8.6 | 0.6% | Mar 19, 2026 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net... |
| CVE-2026-26136 | HIGH | 7.5 | 0.7% | Mar 19, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut... |
| CVE-2026-26120 | HIGH | 7.5 | 0.6% | Mar 19, 2026 | Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network... |
| CVE-2026-23659 | HIGH | 7.5 | 0.8% | Mar 19, 2026 | Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disc... |
| CVE-2026-25667 | HIGH | 7.5 | 3.0% | Mar 19, 2026 | ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause ex... |
| CVE-2026-2646 | HIGH | 8.1 | 0.1% | Mar 19, 2026 | A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session ... |
| CVE-2026-2645 | HIGH | 7.5 | 0.1% | Mar 19, 2026 | In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could ... |
| CVE-2026-30403 | HIGH | 7.5 | 0.4% | Mar 19, 2026 | There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud ... |
| CVE-2026-0819 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. In wc_PKCS7_BuildSign... |
| CVE-2026-3029 | HIGH | 7.5 | 0.4% | Mar 19, 2026 | A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF ver... |
| CVE-2026-30404 | HIGH | 7.5 | 0.3% | Mar 19, 2026 | The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulne... |
| CVE-2026-4424 | HIGH | 7.5 | 1.2% | Mar 19, 2026 | A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic du... |
| CVE-2026-30711 | HIGH | 8.8 | 0.3% | Mar 19, 2026 | Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/session.... |
| CVE-2026-27043 | HIGH | 7.2 | 0.4% | Mar 19, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue... |
| CVE-2026-22558 | HIGH | 7.7 | 0.5% | Mar 19, 2026 | An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with aut... |
| CVE-2026-3658 | HIGH | 7.5 | 0.3% | Mar 19, 2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL... |
| CVE-2026-3511 | HIGH | 8.6 | 0.3% | Mar 19, 2026 | Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allow... |
| CVE-2026-27070 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest ... |
| CVE-2026-27068 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard Websit... |
| CVE-2026-25445 | HIGH | 8.8 | 0.3% | Mar 19, 2026 | Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This is... |
| CVE-2026-25443 | HIGH | 7.5 | 0.2% | Mar 19, 2026 | Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-an... |
| CVE-2026-25442 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes Kenth... |
| CVE-2026-25438 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenber... |
| CVE-2026-25471 | HIGH | 8.1 | 0.3% | Mar 19, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themepaste Admin Safety Guard admin-safety-gua... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now