2026 CVE Vulnerabilities

69,861 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30842MEDIUM4.3Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, Wallos allows an authenti...
CVE-2026-30841MEDIUM6.1Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, passwordreset.php outputs...
CVE-2026-30840HIGH8.8Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side re...
CVE-2026-30839MEDIUM4.3Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, testwebhooknotifications....
CVE-2026-30830MEDIUM6.1Defuddle cleans up HTML pages. Prior to version 0.9.0, the _findContentBySchemaText method in src/defuddle.ts interpolat...
CVE-2026-30829MEDIUM5.3Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and...
CVE-2026-30828HIGH7.5Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be ...
CVE-2026-30827HIGH7.5express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to version...
CVE-2026-30825MEDIUM6.5hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke e...
CVE-2026-30824CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NV...
CVE-2026-30823HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there ...
CVE-2026-27797MEDIUM5.3Homarr is an open-source dashboard. Prior to version 1.54.0, an unauthenticated Server-Side Request Forgery (SSRF) vulne...
CVE-2026-27796HIGH7.5Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a...
CVE-2026-30822HIGH7.7Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauth...
CVE-2026-30821CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /a...
CVE-2026-30820HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowis...
CVE-2026-30247HIGH7.5WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0....
CVE-2026-3352HIGH7.2The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0...
CVE-2026-2722MEDIUM4.8The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up...
CVE-2026-2721MEDIUM4.8The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up...
CVE-2026-2494MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2026-2488MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message delet...
CVE-2026-2431MEDIUM6.1The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date...
CVE-2026-2429MEDIUM4.9The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'ce_venue_name' CSV field in the `on_sa...
CVE-2026-2020HIGH7.5The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now