2026 CVE Vulnerabilities
55,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28773 | HIGH | 8.8 | 2.1% | Mar 4, 2026 | The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series Sup... |
| CVE-2026-28770 | HIGH | 8.8 | 0.4% | Mar 4, 2026 | Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corp... |
| CVE-2026-2025 | HIGH | 7.5 | 1.4% | Mar 4, 2026 | The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unau... |
| CVE-2026-3452 | HIGH | 7.2 | 0.6% | Mar 4, 2026 | Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express ... |
| CVE-2026-1945 | HIGH | 7.2 | 0.3% | Mar 4, 2026 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_ema... |
| CVE-2026-1273 | HIGH | 7.2 | 0.3% | Mar 4, 2026 | The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-S... |
| CVE-2026-28289 | HIGH | 8.1 | 31.1% | Mar 3, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-... |
| CVE-2026-27981 | HIGH | 7.4 | 0.3% | Mar 3, 2026 | HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) ... |
| CVE-2026-27932 | HIGH | 7.5 | 0.4% | Mar 3, 2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar... |
| CVE-2026-27905 | HIGH | 7.8 | 0.3% | Mar 3, 2026 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.... |
| CVE-2026-27622 | HIGH | 7.8 | 0.2% | Mar 3, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-3487 | HIGH | 7.2 | 0.4% | Mar 3, 2026 | A vulnerability was found in itsourcecode College Management System 1.0. This issue affects some unknown processing of t... |
| CVE-2026-25146 | HIGH | 8.1 | 0.4% | Mar 3, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to b... |
| CVE-2026-1775 | HIGH | 8.8 | 0.8% | Mar 3, 2026 | The Labkotec LID-3300IP has an existing vulnerability in the ice detector software that enables an unauthenticated attac... |
| CVE-2026-3486 | HIGH | 7.2 | 0.3% | Mar 3, 2026 | A vulnerability has been found in itsourcecode College Management System 1.0. This vulnerability affects unknown code of... |
| CVE-2026-25906 | HIGH | 7.8 | 0.2% | Mar 3, 2026 | Dell Optimizer, versions prior to 6.3.1, contain an Improper Link Resolution Before File Access ('Link Following') vulne... |
| CVE-2026-24502 | HIGH | 7.8 | 0.2% | Mar 3, 2026 | Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerabilit... |
| CVE-2026-1567 | HIGH | 7.5 | 0.3% | Mar 3, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere... |
| CVE-2026-3484 | HIGH | 8.8 | 2.6% | Mar 3, 2026 | A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected ... |
| CVE-2026-2915 | HIGH | 7.1 | 0.1% | Mar 3, 2026 | HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability ... |
| CVE-2026-29022 | HIGH | 7.8 | 0.2% | Mar 3, 2026 | dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in th... |
| CVE-2026-26892 | HIGH | 7.2 | 0.3% | Mar 3, 2026 | Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php. |
| CVE-2026-0869 | HIGH | 8.8 | 0.4% | Mar 3, 2026 | Authentication bypass in Brocade ASCG 3.4.0 Could allow an unauthorized user to perform ASCG operations related to Broca... |
| CVE-2026-3437 | HIGH | 7.8 | 0.2% | Mar 3, 2026 | An improper restriction of operations within the bounds of a memory buffer vulnerability in Portwell Engineering Toolkit... |
| CVE-2026-2637 | HIGH | 7.8 | 0.2% | Mar 3, 2026 | iBoysoft NTFS for Mac contains a local privilege escalation vulnerability in its privileged helper daemon ntfshelperd. T... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now