2026 CVE Vulnerabilities
69,850 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30913 | MEDIUM | 4.6 | 0.2% | Mar 10, 2026 | Flarum is open-source forum software. When the flarum/nicknames extension is enabled, a registered user can set their ni... |
| CVE-2026-30887 | CRITICAL | 9.9 | 0.4% | Mar 10, 2026 | OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members ... |
| CVE-2026-30885 | MEDIUM | 5.3 | 0.4% | Mar 10, 2026 | WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns al... |
| CVE-2026-30870 | MEDIUM | 6.5 | 0.2% | Mar 10, 2026 | PowerSync Service is the server-side component of the PowerSync sync engine. In version 1.20.0, when using new sync stre... |
| CVE-2026-30869 | CRITICAL | 9.8 | 1.0% | Mar 10, 2026 | SiYuan is a personal knowledge management system. Prior to 3.5.10, a path traversal vulnerability in the /export endpoin... |
| CVE-2026-30862 | CRITICAL | 9 | 0.3% | Mar 10, 2026 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulne... |
| CVE-2026-2364 | HIGH | 7.3 | 0.1% | Mar 10, 2026 | If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low pr... |
| CVE-2026-29773 | MEDIUM | 4.3 | 0.2% | Mar 10, 2026 | Kubewarden is a policy engine for Kubernetes. Kubewarden cluster operators can grant permissions to users to deploy name... |
| CVE-2026-28513 | HIGH | 7.1 | 0.3% | Mar 10, 2026 | Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.4.0, th... |
| CVE-2026-28512 | MEDIUM | 6.1 | 0.2% | Mar 10, 2026 | Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. From 2.0.0 to befo... |
| CVE-2026-28281 | HIGH | 7.1 | 0.1% | Mar 10, 2026 | InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF token... |
| CVE-2026-28267 | MEDIUM | 6.8 | 0.1% | Mar 10, 2026 | Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwrit... |
| CVE-2026-27689 | HIGH | 7.7 | 0.4% | Mar 10, 2026 | Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular us... |
| CVE-2026-27688 | MEDIUM | 5 | 0.2% | Mar 10, 2026 | Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with user p... |
| CVE-2026-27687 | MEDIUM | 5.8 | 0.3% | Mar 10, 2026 | Due to missing authorization check in SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal, a user with high privileges cou... |
| CVE-2026-27686 | MEDIUM | 5.9 | 0.2% | Mar 10, 2026 | Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform un... |
| CVE-2026-27685 | CRITICAL | 9.1 | 0.6% | Mar 10, 2026 | SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content... |
| CVE-2026-27684 | MEDIUM | 6.4 | 0.3% | Mar 10, 2026 | SAP NetWeaver Feedback Notifications Service contains a SQL injection vulnerability that allows an authenticated attacke... |
| CVE-2026-24317 | MEDIUM | 5 | 0.2% | Mar 10, 2026 | SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated ... |
| CVE-2026-24316 | MEDIUM | 6.4 | 0.2% | Mar 10, 2026 | SAP NetWeaver Application Server for ABAP provides an ABAP Report for testing purposes, which allows to send HTTP reques... |
| CVE-2026-24313 | MEDIUM | 5 | 0.2% | Mar 10, 2026 | SAP Solution Tools Plug-In (ST-PI) contains a function module that does not perform the necessary authorization checks f... |
| CVE-2026-24311 | MEDIUM | 5.6 | 0.1% | Mar 10, 2026 | The SAP Customer Checkout application exhibits certain design characteristics that involve locally storing operational d... |
| CVE-2026-24310 | MEDIUM | 4.3 | 0.2% | Mar 10, 2026 | Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute... |
| CVE-2026-24309 | MEDIUM | 6.4 | 0.2% | Mar 10, 2026 | Due to missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker could execute... |
| CVE-2026-1920 | MEDIUM | 5.3 | 0.2% | Mar 10, 2026 | The Booking Calendar for Appointments and Service Businesses – Booktics plugin for WordPress is vulnerable to unauthoriz... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now