2026 CVE Vulnerabilities
69,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-29184 | MEDIUM | 6.5 | 0.3% | Mar 7, 2026 | Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template c... |
| CVE-2026-29067 | CRITICAL | 9.3 | 0.3% | Mar 7, 2026 | ZITADEL is an open source identity management platform. From version 4.0.0-rc.1 to 4.7.0, a potential vulnerability exis... |
| CVE-2026-3662 | HIGH | 7.2 | 11.2% | Mar 7, 2026 | A vulnerability has been found in Wavlink WL-NU516U1 240425. This vulnerability affects the function usb_p910 of the fil... |
| CVE-2026-3661 | HIGH | 7.2 | 10.9% | Mar 7, 2026 | A flaw has been found in Wavlink WL-NU516U1 240425. This affects the function ota_new_upgrade of the file /cgi-bin/adm.c... |
| CVE-2026-2219 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate t... |
| CVE-2026-24308 | HIGH | 7.5 | 1.2% | Mar 7, 2026 | Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an att... |
| CVE-2026-24281 | HIGH | 7.4 | 0.6% | Mar 7, 2026 | Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, a... |
| CVE-2026-2433 | MEDIUM | 6.1 | 0.2% | Mar 7, 2026 | The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to DOM-Ba... |
| CVE-2026-2420 | MEDIUM | 4.4 | 0.2% | Mar 7, 2026 | The LotekMedia Popup Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in a... |
| CVE-2026-1825 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The Show YouTube video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'syv' shortcod... |
| CVE-2026-1824 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The Infomaniak Connect for OpenID plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'endpoint_lo... |
| CVE-2026-1823 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The Consensus Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's consensus shortco... |
| CVE-2026-1820 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The Media Library Alt Text Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bv... |
| CVE-2026-1805 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The DA Media GigList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's damedia_giglist ... |
| CVE-2026-1574 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The MyQtip – easy qTip2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `myqtip` shor... |
| CVE-2026-1569 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The Wueen plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wueen-blocket` shortcode i... |
| CVE-2026-1087 | MEDIUM | 4.3 | 0.1% | Mar 7, 2026 | The Guardian News Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2026-1086 | MEDIUM | 4.3 | 0.1% | Mar 7, 2026 | The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi... |
| CVE-2026-1085 | MEDIUM | 4.3 | 0.1% | Mar 7, 2026 | The True Ranker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2... |
| CVE-2026-1074 | HIGH | 7.2 | 0.2% | Mar 7, 2026 | The WP App Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app-bar-features' parameter in... |
| CVE-2026-1073 | MEDIUM | 4.3 | 0.1% | Mar 7, 2026 | The Purchase Button For Affiliate Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ... |
| CVE-2026-1071 | MEDIUM | 4.4 | 0.2% | Mar 7, 2026 | The Carta Online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up... |
| CVE-2026-30842 | MEDIUM | 4.3 | 0.3% | Mar 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, Wallos allows an authenti... |
| CVE-2026-30841 | MEDIUM | 6.1 | 0.3% | Mar 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, passwordreset.php outputs... |
| CVE-2026-30840 | HIGH | 8.8 | 0.5% | Mar 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side re... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now