2026 CVE Vulnerabilities
53,578 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31386 | HIGH | 8.6 | 1.5% | Mar 16, 2026 | OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An a... |
| CVE-2026-2923 | HIGH | 7.8 | 0.7% | Mar 16, 2026 | GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attack... |
| CVE-2026-2922 | HIGH | 7.8 | 0.4% | Mar 16, 2026 | GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote at... |
| CVE-2026-2921 | HIGH | 7.8 | 0.9% | Mar 16, 2026 | GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers ... |
| CVE-2026-2920 | HIGH | 7.8 | 0.8% | Mar 16, 2026 | GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2026-2493 | HIGH | 7.5 | 3.9% | Mar 16, 2026 | IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attacke... |
| CVE-2026-28522 | HIGH | 7.1 | 0.3% | Mar 16, 2026 | arduino-TuyaOpen before version 1.2.1 contains a null pointer dereference vulnerability in the WiFiUDP component. An att... |
| CVE-2026-28521 | HIGH | 7.7 | 0.2% | Mar 16, 2026 | arduino-TuyaOpen before version 1.2.1 contains an out-of-bounds memory read vulnerability in the TuyaIoT component. An a... |
| CVE-2026-28520 | HIGH | 8.6 | 0.2% | Mar 16, 2026 | arduino-TuyaOpen before version 1.2.1 contains a single-byte buffer overflow vulnerability in the WiFiMulti component. W... |
| CVE-2026-28519 | HIGH | 8.8 | 0.4% | Mar 16, 2026 | arduino-TuyaOpen before version 1.2.1 contains a heap-based buffer overflow vulnerability in the DnsServer component. An... |
| CVE-2026-26133 | HIGH | 7.1 | 0.4% | Mar 16, 2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-25083 | HIGH | 8.7 | 0.3% | Mar 16, 2026 | GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logg... |
| CVE-2026-24458 | HIGH | 7.5 | 0.3% | Mar 16, 2026 | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords,... |
| CVE-2026-20999 | HIGH | 7.5 | 0.3% | Mar 16, 2026 | Authentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged... |
| CVE-2026-20990 | HIGH | 8.1 | 0.2% | Mar 16, 2026 | Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attacker... |
| CVE-2026-1947 | HIGH | 7.5 | 0.3% | Mar 16, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Referen... |
| CVE-2026-0977 | HIGH | 7.1 | 0.2% | Mar 16, 2026 | IBM CICS Transaction Gateway for Multiplatforms 9.3 and 10.1 could allow a user to transfer or view files due to imprope... |
| CVE-2026-4111 | HIGH | 7.5 | 0.7% | Mar 13, 2026 | A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive... |
| CVE-2026-4092 | HIGH | 8.8 | 0.5% | Mar 13, 2026 | Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malic... |
| CVE-2026-3999 | HIGH | 8.8 | 0.3% | Mar 13, 2026 | A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability... |
| CVE-2026-3910 | HIGH | 8.8 | 2.0% | Mar 13, 2026 | Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrar... |
| CVE-2026-3909 | HIGH | 8.8 | 1.6% | Mar 13, 2026 | Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds m... |
| CVE-2026-3873 | HIGH | 7.2 | 0.2% | Mar 13, 2026 | Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by ACLs.... |
| CVE-2026-3045 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized acces... |
| CVE-2026-32597 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now