2026 CVE Vulnerabilities
55,393 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23815 | HIGH | 7.2 | 0.9% | Mar 11, 2026 | A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high p... |
| CVE-2026-23814 | HIGH | 8.8 | 0.5% | Mar 11, 2026 | A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remo... |
| CVE-2026-3453 | HIGH | 8.1 | 0.4% | Mar 11, 2026 | The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu... |
| CVE-2026-21361 | HIGH | 8.1 | 0.4% | Mar 11, 2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a ... |
| CVE-2026-21311 | HIGH | 8 | 0.3% | Mar 11, 2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a ... |
| CVE-2026-21309 | HIGH | 7.5 | 0.6% | Mar 11, 2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an... |
| CVE-2026-21290 | HIGH | 8.7 | 0.5% | Mar 11, 2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a ... |
| CVE-2026-21289 | HIGH | 7.5 | 0.6% | Mar 11, 2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an... |
| CVE-2026-21284 | HIGH | 8.1 | 0.4% | Mar 11, 2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a ... |
| CVE-2026-27272 | HIGH | 7.8 | 0.1% | Mar 10, 2026 | Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in ... |
| CVE-2026-27271 | HIGH | 7.8 | 0.2% | Mar 10, 2026 | Illustrator versions 29.8.4, 30.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resu... |
| CVE-2026-27267 | HIGH | 7.8 | 0.2% | Mar 10, 2026 | Illustrator versions 29.8.4, 30.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could res... |
| CVE-2026-21362 | HIGH | 7.8 | 0.1% | Mar 10, 2026 | Illustrator versions 29.8.4, 30.1 and earlier are affected by an out-of-bounds write vulnerability that could result in ... |
| CVE-2026-21333 | HIGH | 8.6 | 0.2% | Mar 10, 2026 | Illustrator versions 29.8.4, 30.1 and earlier are affected by an Untrusted Search Path vulnerability that might allow at... |
| CVE-2026-31837 | HIGH | 7.5 | 0.4% | Mar 10, 2026 | Istio is an open platform to connect, manage, and secure microservices. Prior to 1.29.1, 1.28.5, and 1.27.8, a user of I... |
| CVE-2026-31834 | HIGH | 7.2 | 0.3% | Mar 10, 2026 | Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identi... |
| CVE-2026-31830 | HIGH | 7.5 | 0.2% | Mar 10, 2026 | sigstore-ruby is a pure Ruby implementation of the sigstore verify command from the sigstore/cosign project. Prior to 0.... |
| CVE-2026-31829 | HIGH | 8.8 | 2.3% | Mar 10, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise expose... |
| CVE-2026-31828 | HIGH | 8.8 | 0.4% | Mar 10, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a... |
| CVE-2026-31827 | HIGH | 7.1 | 0.2% | Mar 10, 2026 | Alienbin is an anonymous code and text sharing web service. In 1.0.0 and earlier, the /save endpoint in server.js drops ... |
| CVE-2026-31817 | HIGH | 8.5 | 0.7% | Mar 10, 2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature i... |
| CVE-2026-28807 | HIGH | 7.5 | 1.1% | Mar 10, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in gleam-wisp wisp allows a... |
| CVE-2026-28806 | HIGH | 8.8 | 0.4% | Mar 10, 2026 | Improper Authorization vulnerability in nerves-hub nerves_hub_web allows cross-organization device control via device bu... |
| CVE-2026-27278 | HIGH | 7.8 | 0.2% | Mar 10, 2026 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerabil... |
| CVE-2026-27220 | HIGH | 7.8 | 0.4% | Mar 10, 2026 | Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerabil... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now