2026 CVE Vulnerabilities
55,748 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22397 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22395 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22394 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22392 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22389 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22387 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-22385 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-2365 | HIGH | 7.2 | 0.3% | Mar 5, 2026 | The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_sav... |
| CVE-2026-29127 | HIGH | 7.8 | 0.2% | Mar 5, 2026 | The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. ... |
| CVE-2026-26034 | HIGH | 8.5 | 0.2% | Mar 5, 2026 | UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vul... |
| CVE-2026-26033 | HIGH | 8.4 | 0.2% | Mar 5, 2026 | UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Unquoted Search Path or Element (CWE-428) v... |
| CVE-2026-29126 | HIGH | 7.8 | 0.1% | Mar 5, 2026 | Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) ... |
| CVE-2026-29124 | HIGH | 7.8 | 0.1% | Mar 5, 2026 | Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DP... |
| CVE-2026-29123 | HIGH | 7.8 | 0.1% | Mar 5, 2026 | A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a l... |
| CVE-2026-29121 | HIGH | 7.8 | 0.1% | Mar 5, 2026 | International Data Casting (IDC) SFX2100 satellite receiver comes with the `/sbin/ip` utility installed with the setuid ... |
| CVE-2026-2836 | HIGH | 8.1 | 0.4% | Mar 5, 2026 | A cache poisoning vulnerability has been found in the Pingora HTTP proxy framework’s default cache key construction. The... |
| CVE-2026-27803 | HIGH | 8.3 | 0.3% | Mar 4, 2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to versi... |
| CVE-2026-27802 | HIGH | 8.3 | 0.3% | Mar 4, 2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to versi... |
| CVE-2026-25750 | HIGH | 8.1 | 0.3% | Mar 4, 2026 | Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm ver... |
| CVE-2026-3544 | HIGH | 8.8 | 0.3% | Mar 4, 2026 | Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out o... |
| CVE-2026-3543 | HIGH | 8.8 | 0.3% | Mar 4, 2026 | Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially per... |
| CVE-2026-3542 | HIGH | 8.8 | 0.3% | Mar 4, 2026 | Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perfor... |
| CVE-2026-3541 | HIGH | 8.8 | 0.3% | Mar 4, 2026 | Inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out... |
| CVE-2026-3540 | HIGH | 8.8 | 0.3% | Mar 4, 2026 | Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform o... |
| CVE-2026-3538 | HIGH | 8.8 | 0.4% | Mar 4, 2026 | Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out o... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now