2026 CVE Vulnerabilities
53,582 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0954 | HIGH | 8.5 | 0.2% | Mar 13, 2026 | There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted DSB file in Digilent D... |
| CVE-2026-2229 | HIGH | 7.5 | 0.9% | Mar 12, 2026 | ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_m... |
| CVE-2026-1528 | HIGH | 7.5 | 0.5% | Mar 12, 2026 | ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's Byt... |
| CVE-2026-1526 | HIGH | 7.5 | 1.1% | Mar 12, 2026 | The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessa... |
| CVE-2026-32274 | HIGH | 7.5 | 0.6% | Mar 12, 2026 | Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes ... |
| CVE-2026-3497 | HIGH | 7.5 | 2.2% | Mar 12, 2026 | Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI... |
| CVE-2026-32247 | HIGH | 8.1 | 0.3% | Mar 12, 2026 | Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2... |
| CVE-2026-32246 | HIGH | 7.1 | 0.3% | Mar 12, 2026 | Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users wit... |
| CVE-2026-32242 | HIGH | 7.4 | 0.3% | Mar 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32236 | HIGH | 7.5 | 0.3% | Mar 12, 2026 | Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF) vul... |
| CVE-2026-32231 | HIGH | 8.2 | 0.2% | Mar 12, 2026 | ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields... |
| CVE-2026-32138 | HIGH | 8.2 | 0.3% | Mar 12, 2026 | NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. P... |
| CVE-2026-3841 | HIGH | 8.8 | 1.8% | Mar 12, 2026 | A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5... |
| CVE-2026-32141 | HIGH | 7.5 | 0.8% | Mar 12, 2026 | flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve... |
| CVE-2026-32140 | HIGH | 8.8 | 0.7% | Mar 12, 2026 | Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an ... |
| CVE-2026-32137 | HIGH | 8.8 | 0.4% | Mar 12, 2026 | Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasourc... |
| CVE-2026-32129 | HIGH | 8.7 | 0.2% | Mar 12, 2026 | soroban-poseidon provides Poseidon and Poseidon2 cryptographic hash functions for Soroban smart contracts. Poseidon V1 (... |
| CVE-2026-32116 | HIGH | 8.1 | 0.4% | Mar 12, 2026 | Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 ... |
| CVE-2026-28254 | HIGH | 7.5 | 0.3% | Mar 12, 2026 | A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticate... |
| CVE-2026-28253 | HIGH | 7.5 | 0.3% | Mar 12, 2026 | A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could a... |
| CVE-2026-26794 | HIGH | 8.8 | 0.5% | Mar 12, 2026 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This v... |
| CVE-2026-28793 | HIGH | 8.4 | 0.2% | Mar 12, 2026 | Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints... |
| CVE-2026-28791 | HIGH | 7.4 | 0.3% | Mar 12, 2026 | Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS devel... |
| CVE-2026-28356 | HIGH | 7.5 | 0.7% | Mar 12, 2026 | multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header... |
| CVE-2026-27940 | HIGH | 7.8 | 0.2% | Mar 12, 2026 | llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now