2026 CVE Vulnerabilities
53,618 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31862 | HIGH | 8.8 | 0.4% | Mar 11, 2026 | Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1... |
| CVE-2026-31861 | HIGH | 8.8 | 6.0% | Mar 11, 2026 | Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1... |
| CVE-2026-31858 | HIGH | 8.8 | 0.4% | Mar 11, 2026 | Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() ... |
| CVE-2026-31857 | HIGH | 8.8 | 0.7% | Mar 11, 2026 | Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in t... |
| CVE-2026-30226 | HIGH | 7.5 | 0.4% | Mar 11, 2026 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the ... |
| CVE-2026-31854 | HIGH | 8.8 | 0.3% | Mar 11, 2026 | Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted i... |
| CVE-2026-31839 | HIGH | 7.5 | 0.1% | Mar 11, 2026 | Striae is a firearms examiner's comparison companion. A high-severity integrity bypass vulnerability existed in Striae's... |
| CVE-2026-30868 | HIGH | 8.1 | 0.1% | Mar 11, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform ... |
| CVE-2026-30239 | HIGH | 7.1 | 0.2% | Mar 11, 2026 | OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the wor... |
| CVE-2026-20163 | HIGH | 7.2 | 0.5% | Mar 11, 2026 | In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.251... |
| CVE-2026-20074 | HIGH | 7.4 | 0.2% | Mar 11, 2026 | A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR... |
| CVE-2026-20046 | HIGH | 8.8 | 0.1% | Mar 11, 2026 | A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticate... |
| CVE-2026-20040 | HIGH | 8.8 | 0.2% | Mar 11, 2026 | A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary co... |
| CVE-2026-31892 | HIGH | 8.1 | 0.4% | Mar 11, 2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.... |
| CVE-2026-28229 | HIGH | 7.5 | 0.7% | Mar 11, 2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t... |
| CVE-2026-27897 | HIGH | 7.1 | 0.6% | Mar 11, 2026 | Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability e... |
| CVE-2026-22248 | HIGH | 8.8 | 0.3% | Mar 11, 2026 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track... |
| CVE-2026-21888 | HIGH | 7.5 | 0.3% | Mar 11, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. MQTT v5 Variable Byte Integer parsing out-of-bound... |
| CVE-2026-1497 | HIGH | 7.2 | 0.2% | Mar 11, 2026 | Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.... |
| CVE-2026-1069 | HIGH | 7.5 | 0.4% | Mar 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an... |
| CVE-2026-3013 | HIGH | 8.7 | 0.5% | Mar 11, 2026 | Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attac... |
| CVE-2026-30902 | HIGH | 7.8 | 0.1% | Mar 11, 2026 | Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user to conduct an escalati... |
| CVE-2026-30901 | HIGH | 7.8 | 0.1% | Mar 11, 2026 | Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduc... |
| CVE-2026-30900 | HIGH | 7.8 | 0.1% | Mar 11, 2026 | Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated... |
| CVE-2026-3496 | HIGH | 7.5 | 0.3% | Mar 11, 2026 | The JetBooking plugin for WordPress is vulnerable to SQL Injection via the 'check_in_date' parameter in all versions up ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now