2026 CVE Vulnerabilities
53,576 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2579 | HIGH | 7.5 | 0.3% | Mar 17, 2026 | The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via th... |
| CVE-2026-4289 | HIGH | 7.3 | 0.3% | Mar 17, 2026 | A security vulnerability has been detected in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This affects an ... |
| CVE-2026-4288 | HIGH | 7.3 | 0.3% | Mar 17, 2026 | A weakness has been identified in Tiandy Easy7 Integrated Management Platform 7.17.0. The impacted element is an unknown... |
| CVE-2026-4287 | HIGH | 7.3 | 0.3% | Mar 17, 2026 | A security flaw has been discovered in Tiandy Easy7 Integrated Management Platform 7.17.0. The affected element is an un... |
| CVE-2026-2454 | HIGH | 8.6 | 0.3% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array le... |
| CVE-2026-29522 | HIGH | 8.7 | 1.0% | Mar 16, 2026 | ZwickRoell Test Data Management versions prior to 3.0.8 contain a local file inclusion (LFI) vulnerability in the /serve... |
| CVE-2026-32264 | HIGH | 7.2 | 0.5% | Mar 16, 2026 | Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-R... |
| CVE-2026-32263 | HIGH | 7.2 | 0.5% | Mar 16, 2026 | Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTyp... |
| CVE-2026-30881 | HIGH | 8.8 | 0.3% | Mar 16, 2026 | Chamilo LMS is a learning management system. Version 1.11.34 and prior contains a SQL Injection vulnerability in the sta... |
| CVE-2026-30875 | HIGH | 8.8 | 0.5% | Mar 16, 2026 | Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P... |
| CVE-2026-32261 | HIGH | 8.5 | 0.4% | Mar 16, 2026 | Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS, which will send GET or POST requests w... |
| CVE-2026-4269 | HIGH | 7.5 | 0.2% | Mar 16, 2026 | A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote a... |
| CVE-2026-4253 | HIGH | 7.2 | 6.5% | Mar 16, 2026 | A security flaw has been discovered in Tenda AC8 16.03.50.11. This affects the function route_set_user_policy_rule of th... |
| CVE-2026-4224 | HIGH | 7.5 | 0.6% | Mar 16, 2026 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply ... |
| CVE-2026-3644 | HIGH | 7.5 | 0.5% | Mar 16, 2026 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()... |
| CVE-2026-28498 | HIGH | 7.5 | 0.2% | Mar 16, 2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulne... |
| CVE-2026-23862 | HIGH | 7.8 | 0.4% | Mar 16, 2026 | Dell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a C... |
| CVE-2026-30405 | HIGH | 7.5 | 0.3% | Mar 16, 2026 | An issue in GoBGP gobgpd v.4.2.0 allows a remote attacker to cause a denial of service via the NEXT_HOP path attribute |
| CVE-2026-4276 | HIGH | 7.5 | 0.3% | Mar 16, 2026 | LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries. |
| CVE-2026-25369 | HIGH | 7.1 | 0.1% | Mar 16, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexmls Flexmls® I... |
| CVE-2026-4255 | HIGH | 7.8 | 0.2% | Mar 16, 2026 | A DLL search order hijacking vulnerability in Thermalright TR-VISION HOME on Windows (64-bit) allows a local attacker to... |
| CVE-2026-4240 | HIGH | 7.5 | 0.5% | Mar 16, 2026 | A vulnerability was determined in Open5GS up to 2.7.6. The affected element is the function smf_gx_cca_cb/smf_gy_cca_cb/... |
| CVE-2026-4237 | HIGH | 7.3 | 0.3% | Mar 16, 2026 | A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. This vulnerability affects unknown code of the ... |
| CVE-2026-4236 | HIGH | 7.3 | 0.3% | Mar 16, 2026 | A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function... |
| CVE-2026-4235 | HIGH | 7.3 | 0.3% | Mar 16, 2026 | A weakness has been identified in itsourcecode Online Enrollment System 1.0. This issue affects some unknown processing ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now