2026 CVE Vulnerabilities
69,831 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30921 | CRITICAL | 9.9 | 0.4% | Mar 10, 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.20, OneUptime Synthetic Monitors allo... |
| CVE-2026-30920 | HIGH | 8.6 | 0.2% | Mar 10, 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback t... |
| CVE-2026-30919 | MEDIUM | 5.4 | 0.2% | Mar 10, 2026 | facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as... |
| CVE-2026-30918 | MEDIUM | 6.1 | 0.2% | Mar 10, 2026 | facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs wh... |
| CVE-2026-30917 | HIGH | 8.8 | 0.3% | Mar 10, 2026 | Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be i... |
| CVE-2026-30916 | — | — | — | Mar 10, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: Further investigation determined that the softwa... |
| CVE-2026-30913 | MEDIUM | 4.6 | 0.2% | Mar 10, 2026 | Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their ni... |
| CVE-2026-30887 | CRITICAL | 9.9 | 0.4% | Mar 10, 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members ... |
| CVE-2026-30885 | MEDIUM | 5.3 | 0.4% | Mar 10, 2026 | WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns al... |
| CVE-2026-30870 | MEDIUM | 6.5 | 0.2% | Mar 10, 2026 | PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync stre... |
| CVE-2026-30869 | CRITICAL | 9.8 | 1.0% | Mar 10, 2026 | SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoin... |
| CVE-2026-30862 | CRITICAL | 9 | 0.3% | Mar 10, 2026 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulne... |
| CVE-2026-2364 | HIGH | 7.3 | 0.1% | Mar 10, 2026 | If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low pr... |
| CVE-2026-29773 | MEDIUM | 4.3 | 0.2% | Mar 10, 2026 | Kubewarden is a policy engine for Kubernetes. Kubewarden cluster operators can grant permissions to users to deploy name... |
| CVE-2026-28513 | HIGH | 7.1 | 0.3% | Mar 10, 2026 | Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, th... |
| CVE-2026-28512 | MEDIUM | 6.1 | 0.2% | Mar 10, 2026 | Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to befo... |
| CVE-2026-28281 | HIGH | 7.1 | 0.1% | Mar 10, 2026 | InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF token... |
| CVE-2026-28267 | MEDIUM | 6.8 | 0.1% | Mar 10, 2026 | Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwrit... |
| CVE-2026-27689 | HIGH | 7.7 | 0.4% | Mar 10, 2026 | Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us... |
| CVE-2026-27688 | MEDIUM | 5 | 0.2% | Mar 10, 2026 | Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user p... |
| CVE-2026-27687 | MEDIUM | 5.8 | 0.3% | Mar 10, 2026 | Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges cou... |
| CVE-2026-27686 | MEDIUM | 5.9 | 0.2% | Mar 10, 2026 | Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform un... |
| CVE-2026-27685 | CRITICAL | 9.1 | 0.6% | Mar 10, 2026 | SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content... |
| CVE-2026-27684 | MEDIUM | 6.4 | 0.3% | Mar 10, 2026 | SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacke... |
| CVE-2026-24317 | MEDIUM | 5 | 0.2% | Mar 10, 2026 | SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now