2026 CVE Vulnerabilities
69,861 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30842 | MEDIUM | 4.3 | 0.3% | Mar 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, Wallos allows an authenti... |
| CVE-2026-30841 | MEDIUM | 6.1 | 0.3% | Mar 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, passwordreset.php outputs... |
| CVE-2026-30840 | HIGH | 8.8 | 0.5% | Mar 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side re... |
| CVE-2026-30839 | MEDIUM | 4.3 | 0.3% | Mar 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, testwebhooknotifications.... |
| CVE-2026-30830 | MEDIUM | 6.1 | 0.3% | Mar 7, 2026 | Defuddle cleans up HTML pages. Prior to version 0.9.0, the _findContentBySchemaText method in src/defuddle.ts interpolat... |
| CVE-2026-30829 | MEDIUM | 5.3 | 0.4% | Mar 7, 2026 | Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and... |
| CVE-2026-30828 | HIGH | 7.5 | 0.5% | Mar 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be ... |
| CVE-2026-30827 | HIGH | 7.5 | 0.5% | Mar 7, 2026 | express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to version... |
| CVE-2026-30825 | MEDIUM | 6.5 | 0.2% | Mar 7, 2026 | hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke e... |
| CVE-2026-30824 | CRITICAL | 9.8 | 36.3% | Mar 7, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NV... |
| CVE-2026-30823 | HIGH | 8.8 | 0.4% | Mar 7, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there ... |
| CVE-2026-27797 | MEDIUM | 5.3 | 0.4% | Mar 7, 2026 | Homarr is an open-source dashboard. Prior to version 1.54.0, an unauthenticated Server-Side Request Forgery (SSRF) vulne... |
| CVE-2026-27796 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a... |
| CVE-2026-30822 | HIGH | 7.7 | 12.9% | Mar 7, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauth... |
| CVE-2026-30821 | CRITICAL | 9.8 | 18.3% | Mar 7, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /a... |
| CVE-2026-30820 | HIGH | 8.8 | 0.5% | Mar 7, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowis... |
| CVE-2026-30247 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.... |
| CVE-2026-3352 | HIGH | 7.2 | 0.4% | Mar 7, 2026 | The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0... |
| CVE-2026-2722 | MEDIUM | 4.8 | 0.2% | Mar 7, 2026 | The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up... |
| CVE-2026-2721 | MEDIUM | 4.8 | 0.2% | Mar 7, 2026 | The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up... |
| CVE-2026-2494 | MEDIUM | 4.3 | 0.1% | Mar 7, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery... |
| CVE-2026-2488 | MEDIUM | 4.3 | 0.2% | Mar 7, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message delet... |
| CVE-2026-2431 | MEDIUM | 6.1 | 0.2% | Mar 7, 2026 | The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date... |
| CVE-2026-2429 | MEDIUM | 4.9 | 0.3% | Mar 7, 2026 | The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'ce_venue_name' CSV field in the `on_sa... |
| CVE-2026-2020 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now