2026 CVE Vulnerabilities
55,765 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20039 | HIGH | 8.6 | 0.4% | Mar 4, 2026 | A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secu... |
| CVE-2026-20014 | HIGH | 7.7 | 0.3% | Mar 4, 2026 | A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an ... |
| CVE-2026-20002 | HIGH | 8.1 | 0.3% | Mar 4, 2026 | A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote ... |
| CVE-2026-3520 | HIGH | 7.5 | 0.7% | Mar 4, 2026 | Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allo... |
| CVE-2026-28784 | HIGH | 7.2 | 0.5% | Mar 4, 2026 | Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is possible to craft a malicious payload usi... |
| CVE-2026-28696 | HIGH | 7.5 | 0.4% | Mar 4, 2026 | Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, i... |
| CVE-2026-28695 | HIGH | 7.2 | 0.6% | Mar 4, 2026 | Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Temp... |
| CVE-2026-23809 | HIGH | 7.6 | 0.3% | Mar 4, 2026 | A technique has been identified that adapts a known port-stealing method to Wi-Fi environments that use multiple BSSIDs.... |
| CVE-2026-23808 | HIGH | 8.1 | 0.3% | Mar 4, 2026 | A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to i... |
| CVE-2026-26673 | HIGH | 7.5 | 0.4% | Mar 4, 2026 | An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a de... |
| CVE-2026-26514 | HIGH | 7.5 | 0.4% | Mar 4, 2026 | An Argument Injection vulnerability exists in bird-lg-go before commit 6187a4e. The traceroute module uses shlex.Split t... |
| CVE-2026-23235 | HIGH | 7.1 | 0.2% | Mar 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix out-of-bounds access in sysfs attribute r... |
| CVE-2026-23234 | HIGH | 7.8 | 0.1% | Mar 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid UAF in f2fs_write_end_io() As s... |
| CVE-2026-23233 | HIGH | 7.8 | 0.2% | Mar 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid mapping wrong physical block for... |
| CVE-2026-25907 | HIGH | 7.5 | 0.3% | Mar 4, 2026 | Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism vulnerability. An unau... |
| CVE-2026-23231 | HIGH | 7.8 | 0.8% | Mar 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tabl... |
| CVE-2026-21425 | HIGH | 7.8 | 0.1% | Mar 4, 2026 | Dell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an incorrect privileg... |
| CVE-2026-3094 | HIGH | 7.8 | 0.4% | Mar 4, 2026 | Delta Electronics CNCSoft-G2 lacks proper validation of the user-supplied file. If a user opens a malicious file, an att... |
| CVE-2026-2747 | HIGH | 7.5 | 0.3% | Mar 4, 2026 | SEPPmail Secure Email Gateway before version 15.0.1 decrypts inline PGP messages without isolating them from surrounding... |
| CVE-2026-27444 | HIGH | 7.5 | 0.2% | Mar 4, 2026 | SEPPmail Secure Email Gateway before version 15.0.1 incorrectly interprets email addresses in the email headers, causing... |
| CVE-2026-27443 | HIGH | 7.5 | 0.2% | Mar 4, 2026 | SEPPmail Secure Email Gateway before version 15.0.1 does not properly sanitize the headers from S/MIME protected MIME en... |
| CVE-2026-27442 | HIGH | 7.5 | 0.4% | Mar 4, 2026 | The GINA web interface in SEPPmail Secure Email Gateway before version 15.0.1 does not properly check attachment filenam... |
| CVE-2026-29120 | HIGH | 7.8 | 0.1% | Mar 4, 2026 | The /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2... |
| CVE-2026-28774 | HIGH | 8.8 | 2.4% | Mar 4, 2026 | An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting... |
| CVE-2026-28773 | HIGH | 8.8 | 2.1% | Mar 4, 2026 | The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series Sup... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now