2026 CVE Vulnerabilities
53,599 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32126 | HIGH | 8.1 | 0.3% | Mar 11, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.... |
| CVE-2026-32110 | HIGH | 8.3 | 0.3% | Mar 11, 2026 | SiYuan is a personal knowledge management system. Prior to 3.6.0, the /api/network/forwardProxy endpoint allows authenti... |
| CVE-2026-32106 | HIGH | 7.2 | 0.3% | Mar 11, 2026 | StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the REST API crea... |
| CVE-2026-32103 | HIGH | 7.2 | 0.3% | Mar 11, 2026 | StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the POST /studioc... |
| CVE-2026-2368 | HIGH | 7.1 | 0.1% | Mar 11, 2026 | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user ca... |
| CVE-2026-1716 | HIGH | 7.1 | 0.1% | Mar 11, 2026 | An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiyin... |
| CVE-2026-1715 | HIGH | 7.1 | 0.1% | Mar 11, 2026 | An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiyin... |
| CVE-2026-0940 | HIGH | 8.4 | 0.1% | Mar 11, 2026 | A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local pr... |
| CVE-2026-32098 | HIGH | 7.5 | 0.3% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32097 | HIGH | 8.8 | 0.3% | Mar 11, 2026 | PingPong is a platform for using large language models (LLMs) for teaching and learning. Prior to 7.27.2, an authenticat... |
| CVE-2026-32096 | HIGH | 8.6 | 0.3% | Mar 11, 2026 | Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vul... |
| CVE-2026-31979 | HIGH | 7.8 | 0.2% | Mar 11, 2026 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelbla... |
| CVE-2026-31958 | HIGH | 7.5 | 0.4% | Mar 11, 2026 | Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only l... |
| CVE-2026-31954 | HIGH | 7.3 | 0.1% | Mar 11, 2026 | Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lac... |
| CVE-2026-31895 | HIGH | 8.8 | 0.4% | Mar 11, 2026 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições ass... |
| CVE-2026-31894 | HIGH | 7.5 | 0.4% | Mar 11, 2026 | WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a t... |
| CVE-2026-31889 | HIGH | 8.9 | 0.3% | Mar 11, 2026 | Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration ... |
| CVE-2026-24510 | HIGH | 7.8 | 0.1% | Mar 11, 2026 | Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Privilege Management vulnerabilit... |
| CVE-2026-31887 | HIGH | 7.5 | 0.2% | Mar 11, 2026 | Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for una... |
| CVE-2026-31872 | HIGH | 7.5 | 0.4% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-31870 | HIGH | 7.5 | 0.5% | Mar 11, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib cl... |
| CVE-2026-31866 | HIGH | 7.5 | 0.4% | Mar 11, 2026 | flagd is a feature flag daemon with a Unix philosophy. Prior to 0.14.2, flagd exposes OFREP (/ofrep/v1/evaluate/...) and... |
| CVE-2026-31862 | HIGH | 8.8 | 0.4% | Mar 11, 2026 | Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1... |
| CVE-2026-31861 | HIGH | 8.8 | 6.0% | Mar 11, 2026 | Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1... |
| CVE-2026-31858 | HIGH | 8.8 | 0.4% | Mar 11, 2026 | Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now