2026 CVE Vulnerabilities
53,635 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30949 | HIGH | 8.8 | 0.4% | Mar 10, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a... |
| CVE-2026-30947 | HIGH | 7.5 | 0.4% | Mar 10, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a... |
| CVE-2026-30946 | HIGH | 7.5 | 0.6% | Mar 10, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior 9.5.2-alph... |
| CVE-2026-30837 | HIGH | 7.5 | 0.5% | Mar 10, 2026 | Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communi... |
| CVE-2026-0124 | HIGH | 7.8 | 0.1% | Mar 10, 2026 | There is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege ... |
| CVE-2026-0123 | HIGH | 8.4 | 0.1% | Mar 10, 2026 | In EfwApTransport::ProcessRxRing of efw_ap_transport.cc, there is a possible out of bounds write due to a missing bounds... |
| CVE-2026-0122 | HIGH | 8.4 | 0.1% | Mar 10, 2026 | In multiple places, there is a possible out of bounds write due to memory corruption. This could lead to remote code exe... |
| CVE-2026-0118 | HIGH | 8.4 | 0.1% | Mar 10, 2026 | In oobconfig, there is a possible bypass of carrier restrictions due to a logic error. This could lead to local escalati... |
| CVE-2026-0117 | HIGH | 8.4 | 0.1% | Mar 10, 2026 | In mfc_dec_dqbuf of mfc_dec_v4l2.c, there is a possible out of bounds write due to an incorrect bounds check. This could... |
| CVE-2026-0112 | HIGH | 7.4 | 0.1% | Mar 10, 2026 | In vpu_open_inst of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local es... |
| CVE-2026-0109 | HIGH | 7.5 | 0.3% | Mar 10, 2026 | In dhd_tcpdata_info_get of dhd_ip.c, there is a possible Denial of Service due to a precondition check failure. This cou... |
| CVE-2026-0107 | HIGH | 8.4 | 0.1% | Mar 10, 2026 | In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due to a confused deputy. Th... |
| CVE-2026-2713 | HIGH | 7.8 | 0.1% | Mar 10, 2026 | IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code ... |
| CVE-2026-29174 | HIGH | 8.8 | 0.4% | Mar 10, 2026 | Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in ... |
| CVE-2026-29172 | HIGH | 8.8 | 0.4% | Mar 10, 2026 | Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL In... |
| CVE-2026-28495 | HIGH | 8.8 | 0.3% | Mar 10, 2026 | GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allo... |
| CVE-2026-27825 | HIGH | 8 | 2.3% | Mar 10, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.... |
| CVE-2026-26330 | HIGH | 7.5 | 0.3% | Mar 10, 2026 | Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, At the rate limit f... |
| CVE-2026-26310 | HIGH | 7.5 | 0.4% | Mar 10, 2026 | Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, calling Utility::ge... |
| CVE-2026-26308 | HIGH | 8.2 | 0.3% | Mar 10, 2026 | Envoy is a high-performance edge/middle/service proxy. Prior to 1.37.1, 1.36.5, 1.35.8, and 1.34.13, the Envoy RBAC (Rol... |
| CVE-2026-27826 | HIGH | 8.2 | 13.6% | Mar 10, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to version 0.... |
| CVE-2026-27280 | HIGH | 7.8 | 0.2% | Mar 10, 2026 | DNG SDK versions 1.7.1 2471 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitr... |
| CVE-2026-27279 | HIGH | 7.8 | 0.1% | Mar 10, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by an out-of-bounds write vulnerability that could result i... |
| CVE-2026-27277 | HIGH | 7.8 | 0.2% | Mar 10, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbi... |
| CVE-2026-27276 | HIGH | 7.8 | 0.2% | Mar 10, 2026 | Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now