2026 CVE Vulnerabilities
53,531 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26740 | HIGH | 8.2 | 0.6% | Mar 18, 2026 | Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToE... |
| CVE-2026-23270 | HIGH | 7.8 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: Only allow act_ct to bind to clsact/ingr... |
| CVE-2026-23269 | HIGH | 7.1 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: validate DFA start states are in bounds i... |
| CVE-2026-23268 | HIGH | 7.8 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix unprivileged local user can do privil... |
| CVE-2026-23262 | HIGH | 7.8 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: gve: Fix stats report corruption on queue count cha... |
| CVE-2026-23253 | HIGH | 7.8 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: media: dvb-core: fix wrong reinitialization of ring... |
| CVE-2026-32610 | HIGH | 8.1 | 0.3% | Mar 18, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server... |
| CVE-2026-30345 | HIGH | 7.5 | 0.4% | Mar 18, 2026 | A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitra... |
| CVE-2026-1463 | HIGH | 8.8 | 0.5% | Mar 18, 2026 | The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclu... |
| CVE-2026-3090 | HIGH | 7.2 | 0.2% | Mar 18, 2026 | The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin... |
| CVE-2026-33002 | HIGH | 7.5 | 0.3% | Mar 18, 2026 | Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validatio... |
| CVE-2026-33001 | HIGH | 8.8 | 1.2% | Mar 18, 2026 | Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar a... |
| CVE-2026-2992 | HIGH | 8.2 | 0.2% | Mar 18, 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due t... |
| CVE-2026-2991 | HIGH | 7.3 | 0.4% | Mar 18, 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in a... |
| CVE-2026-24063 | HIGH | 8.2 | 0.1% | Mar 18, 2026 | When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a ... |
| CVE-2026-24062 | HIGH | 7.8 | 0.1% | Mar 18, 2026 | The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signatu... |
| CVE-2026-32609 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | Glances is an open-source system cross-platform monitoring tool. The GHSA-gh4x fix (commit 5d3de60) addressed unauthenti... |
| CVE-2026-32693 | HIGH | 8.8 | 0.3% | Mar 18, 2026 | In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which ... |
| CVE-2026-23248 | HIGH | 7.8 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix refcount bug and potential UAF in pe... |
| CVE-2026-23246 | HIGH | 8.8 | 0.3% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_m... |
| CVE-2026-23245 | HIGH | 7.8 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gate: snapshot parameters with RCU o... |
| CVE-2026-23244 | HIGH | 7.1 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme: fix memory allocation in nvme_pr_read_keys() ... |
| CVE-2026-23243 | HIGH | 7.8 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_writ... |
| CVE-2026-23242 | HIGH | 7.5 | 0.4% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereference in... |
| CVE-2026-22730 | HIGH | 8.8 | 0.5% | Mar 18, 2026 | A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metada... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now