2026 CVE Vulnerabilities
53,579 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31922 | HIGH | 8.5 | 0.2% | Mar 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Fox LMS fo... |
| CVE-2026-31917 | HIGH | 8.5 | 0.3% | Mar 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp ... |
| CVE-2026-31899 | HIGH | 7.5 | 0.5% | Mar 13, 2026 | CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of se... |
| CVE-2026-31886 | HIGH | 7.6 | 0.4% | Mar 13, 2026 | Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the... |
| CVE-2026-31884 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, division by zero in MS-ADPCM and IMA-A... |
| CVE-2026-31882 | HIGH | 7.5 | 0.8% | Mar 13, 2026 | Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, when Dagu is configured with HTTP Basic au... |
| CVE-2026-31814 | HIGH | 7.5 | 0.5% | Mar 13, 2026 | Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. From 0.13.0 to before 0.13.9, a special... |
| CVE-2026-30914 | HIGH | 8.1 | 0.5% | Mar 13, 2026 | SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization d... |
| CVE-2026-30853 | HIGH | 8.2 | 0.2% | Mar 13, 2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a p... |
| CVE-2026-2890 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and includi... |
| CVE-2026-29775 | HIGH | 8.2 | 0.3% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap out-of-bounds read/... |
| CVE-2026-29774 | HIGH | 8.2 | 0.3% | Mar 13, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap buffer overflow occ... |
| CVE-2026-29079 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment ... |
| CVE-2026-29078 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | Lexbor is a web browser engine library. Prior to 2.7.0, the ISO‑2022‑JP encoder in Lexbor fails to reset the temporary s... |
| CVE-2026-25819 | HIGH | 7.5 | 0.5% | Mar 13, 2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23... |
| CVE-2026-25817 | HIGH | 8.8 | 0.8% | Mar 13, 2026 | HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23... |
| CVE-2026-25076 | HIGH | 8.5 | 0.3% | Mar 13, 2026 | Anchore Enterprise versions before 5.25.1 contain an SQL injection vulnerability in the GraphQL Reports API. An authenti... |
| CVE-2026-22199 | HIGH | 8.7 | 1.0% | Mar 13, 2026 | Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi en... |
| CVE-2026-22193 | HIGH | 7.5 | 0.3% | Mar 13, 2026 | wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parame... |
| CVE-2026-22182 | HIGH | 8.7 | 0.5% | Mar 13, 2026 | wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigge... |
| CVE-2026-0957 | HIGH | 8.5 | 0.2% | Mar 13, 2026 | There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted file in Digilent DASYL... |
| CVE-2026-0956 | HIGH | 8.5 | 0.2% | Mar 13, 2026 | There is a memory corruption vulnerability due to an out-of-bounds read when loading a corrupted file in Digilent DASYLa... |
| CVE-2026-0955 | HIGH | 8.5 | 0.2% | Mar 13, 2026 | There is a memory corruption vulnerability due to an out-of-bounds read when loading a corrupted file in Digilent DASYLa... |
| CVE-2026-0954 | HIGH | 8.5 | 0.2% | Mar 13, 2026 | There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted DSB file in Digilent D... |
| CVE-2026-2229 | HIGH | 7.5 | 0.9% | Mar 12, 2026 | ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_m... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now