2026 CVE Vulnerabilities
45,449 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3730 | CRITICAL | 9.8 | 0.4% | Mar 8, 2026 | A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknow... |
| CVE-2026-3723 | CRITICAL | 9.8 | 0.4% | Mar 8, 2026 | A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown fu... |
| CVE-2026-3709 | CRITICAL | 9.8 | 0.4% | Mar 8, 2026 | A weakness has been identified in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown functio... |
| CVE-2026-3708 | CRITICAL | 9.8 | 0.4% | Mar 8, 2026 | A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. The impacted element is an... |
| CVE-2026-3705 | CRITICAL | 9.8 | 0.4% | Mar 8, 2026 | A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. This issue affects some unknown proc... |
| CVE-2026-3703 | CRITICAL | 9.8 | 0.8% | Mar 8, 2026 | A flaw has been found in Wavlink NU516U1 251208. This affects the function sub_401A10 of the file /cgi-bin/login.cgi. Ex... |
| CVE-2026-3696 | CRITICAL | 9.8 | 1.9% | Mar 8, 2026 | A vulnerability was found in Totolink N300RH 6..1c.1353_B20190305. The affected element is the function setWiFiWpsConfig... |
| CVE-2026-30909 | CRITICAL | 9.8 | 0.5% | Mar 8, 2026 | Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows. bin2hex, encrypt, aes256gcm_encryp... |
| CVE-2026-30863 | CRITICAL | 9.8 | 0.5% | Mar 7, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-30860 | CRITICAL | 9.8 | 0.5% | Mar 7, 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.... |
| CVE-2026-30832 | CRITICAL | 9.1 | 0.3% | Mar 7, 2026 | Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authentic... |
| CVE-2026-29191 | CRITICAL | 9.3 | 0.4% | Mar 7, 2026 | ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login... |
| CVE-2026-29186 | CRITICAL | 9.8 | 0.8% | Mar 7, 2026 | Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass v... |
| CVE-2026-29067 | CRITICAL | 9.3 | 0.3% | Mar 7, 2026 | ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exis... |
| CVE-2026-30824 | CRITICAL | 9.8 | 36.3% | Mar 7, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NV... |
| CVE-2026-30821 | CRITICAL | 9.8 | 18.3% | Mar 7, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /a... |
| CVE-2026-25072 | CRITICAL | 9.8 | 0.5% | Mar 7, 2026 | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnera... |
| CVE-2026-25070 | CRITICAL | 9.8 | 3.0% | Mar 7, 2026 | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in... |
| CVE-2026-29063 | CRITICAL | 9.8 | 1.0% | Mar 6, 2026 | Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Po... |
| CVE-2026-30831 | CRITICAL | 9.8 | 0.3% | Mar 6, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.1... |
| CVE-2026-28514 | CRITICAL | 9.8 | 0.5% | Mar 6, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.... |
| CVE-2026-29075 | CRITICAL | 9.8 | 0.4% | Mar 6, 2026 | Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behavi... |
| CVE-2026-26288 | CRITICAL | 9.8 | 0.6% | Mar 6, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat... |
| CVE-2026-26051 | CRITICAL | 9.8 | 0.9% | Mar 6, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat... |
| CVE-2026-2331 | CRITICAL | 9.8 | 0.9% | Mar 6, 2026 | An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileac... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now