2026 CVE Vulnerabilities
53,576 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30707 | HIGH | 8.1 | 0.3% | Mar 17, 2026 | An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control v... |
| CVE-2026-25936 | HIGH | 8.8 | 0.3% | Mar 17, 2026 | GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an auth... |
| CVE-2026-25790 | HIGH | 7.2 | 0.4% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 ... |
| CVE-2026-25772 | HIGH | 7.2 | 0.3% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 ... |
| CVE-2026-25771 | HIGH | 7.5 | 0.5% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.3.0 ... |
| CVE-2026-22882 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2026-20726 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2026-32296 | HIGH | 8.8 | 0.5% | Mar 17, 2026 | Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthent... |
| CVE-2026-32294 | HIGH | 7 | 0.1% | Mar 17, 2026 | JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a comp... |
| CVE-2026-32291 | HIGH | 7 | 0.3% | Mar 17, 2026 | The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requ... |
| CVE-2026-32290 | HIGH | 7 | 0.2% | Mar 17, 2026 | The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware f... |
| CVE-2026-25770 | HIGH | 7.2 | 1.0% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 ... |
| CVE-2026-21570 | HIGH | 8.8 | 0.5% | Mar 17, 2026 | This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, ... |
| CVE-2026-4148 | HIGH | 8.8 | 0.3% | Mar 17, 2026 | A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu... |
| CVE-2026-24901 | HIGH | 8.8 | 0.3% | Mar 17, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (I... |
| CVE-2026-23759 | HIGH | 8.6 | 1.5% | Mar 17, 2026 | Perle IOLAN STS/SCS terminal server models with firmware versions prior to 6.0 allow authenticated OS command injection ... |
| CVE-2026-21886 | HIGH | 8.1 | 0.2% | Mar 17, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.... |
| CVE-2026-4318 | HIGH | 8.8 | 0.5% | Mar 17, 2026 | A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Affected is the function strcpy of the file /goform... |
| CVE-2026-3888 | HIGH | 7.8 | 0.4% | Mar 17, 2026 | Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private ... |
| CVE-2026-4271 | HIGH | 7.5 | 0.8% | Mar 17, 2026 | A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs... |
| CVE-2026-30911 | HIGH | 8.1 | 0.4% | Mar 17, 2026 | Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop... |
| CVE-2026-28779 | HIGH | 7.5 | 0.7% | Mar 17, 2026 | Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configu... |
| CVE-2026-4208 | HIGH | 8.8 | 0.3% | Mar 17, 2026 | The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible M... |
| CVE-2026-1323 | HIGH | 8.8 | 0.2% | Mar 17, 2026 | The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker m... |
| CVE-2026-4258 | HIGH | 7.7 | 0.2% | Mar 17, 2026 | Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to miss... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now