2026 CVE Vulnerabilities
69,888 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-29091 | HIGH | 8.1 | 0.8% | Mar 6, 2026 | Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a ... |
| CVE-2026-29089 | HIGH | 8.8 | 0.1% | Mar 6, 2026 | TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From ve... |
| CVE-2026-29087 | HIGH | 7.5 | 0.3% | Mar 6, 2026 | @hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server... |
| CVE-2026-28514 | CRITICAL | 9.8 | 0.5% | Mar 6, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10.... |
| CVE-2026-29783 | HIGH | 7.8 | 0.4% | Mar 6, 2026 | The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution thro... |
| CVE-2026-29082 | MEDIUM | 5.4 | 0.2% | Mar 6, 2026 | Kestra is an event-driven orchestration platform. In versions from 1.1.10 and prior, Kestra’s execution-file preview ren... |
| CVE-2026-29075 | CRITICAL | 9.8 | 0.4% | Mar 6, 2026 | Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behavi... |
| CVE-2026-29064 | HIGH | 8.2 | 0.2% | Mar 6, 2026 | Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal... |
| CVE-2026-27777 | MEDIUM | 6.9 | 0.2% | Mar 6, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-27764 | HIGH | 8.6 | 0.3% | Mar 6, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ... |
| CVE-2026-27123 | — | — | — | Mar 6, 2026 | Rejected reason: Reason: This candidate was issued in error. |
| CVE-2026-27027 | MEDIUM | 6.9 | 0.2% | Mar 6, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-26288 | CRITICAL | 9.8 | 0.6% | Mar 6, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat... |
| CVE-2026-26018 | HIGH | 7.5 | 1.1% | Mar 6, 2026 | CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDN... |
| CVE-2026-26017 | MEDIUM | 6.3 | 0.4% | Mar 6, 2026 | CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS acce... |
| CVE-2026-24696 | HIGH | 8.7 | 0.4% | Mar 6, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc... |
| CVE-2026-20882 | HIGH | 8.7 | 0.4% | Mar 6, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc... |
| CVE-2026-20748 | HIGH | 8.6 | 0.3% | Mar 6, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ... |
| CVE-2026-2754 | HIGH | 7.5 | 0.5% | Mar 6, 2026 | Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. ... |
| CVE-2026-2753 | HIGH | 7.5 | 0.5% | Mar 6, 2026 | An Absolute Path Traversal vulnerability exists in Navtor NavBox. The application exposes an HTTP service that fails to ... |
| CVE-2026-2752 | MEDIUM | 5.3 | 0.3% | Mar 6, 2026 | Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send ... |
| CVE-2026-26051 | CRITICAL | 9.8 | 0.9% | Mar 6, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat... |
| CVE-2026-1799 | — | — | — | Mar 6, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate has been determined not to be a v... |
| CVE-2026-28106 | MEDIUM | 4.7 | 0.3% | Mar 6, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kings Plugins B2BKing Premium allows Phishing.This ... |
| CVE-2026-28080 | MEDIUM | 4.3 | 0.2% | Mar 6, 2026 | Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Contr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now