2026 CVE Vulnerabilities
69,961 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1128 | MEDIUM | 4.3 | 0.1% | Mar 6, 2026 | The WP eCommerce WordPress plugin through 3.15.1 does not have CSRF check in place when deleting coupons, which could al... |
| CVE-2026-29084 | MEDIUM | 4.6 | 0.1% | Mar 6, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th... |
| CVE-2026-29061 | MEDIUM | 5.4 | 0.1% | Mar 6, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a ... |
| CVE-2026-29060 | MEDIUM | 5 | 0.1% | Mar 6, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a ... |
| CVE-2026-28794 | CRITICAL | 9.8 | 0.9% | Mar 6, 2026 | oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.... |
| CVE-2026-28787 | CRITICAL | 9 | 0.3% | Mar 6, 2026 | OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authenti... |
| CVE-2026-28785 | CRITICAL | 9.8 | 0.4% | Mar 6, 2026 | Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an at... |
| CVE-2026-28685 | MEDIUM | 6.5 | 0.4% | Mar 6, 2026 | Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks... |
| CVE-2026-28683 | HIGH | 8.7 | 0.2% | Mar 6, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, if... |
| CVE-2026-28682 | MEDIUM | 6.4 | 0.1% | Mar 6, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th... |
| CVE-2026-28681 | HIGH | 8.1 | 0.4% | Mar 6, 2026 | Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From ve... |
| CVE-2026-28680 | CRITICAL | 9.3 | 0.2% | Mar 6, 2026 | Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual as... |
| CVE-2026-28679 | HIGH | 7.5 | 0.4% | Mar 6, 2026 | Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0,... |
| CVE-2026-28677 | HIGH | 8.2 | 0.3% | Mar 6, 2026 | OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version... |
| CVE-2026-28676 | HIGH | 8.8 | 0.4% | Mar 6, 2026 | OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version... |
| CVE-2026-28675 | MEDIUM | 5.3 | 0.3% | Mar 6, 2026 | OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version... |
| CVE-2026-28509 | MEDIUM | 5.4 | 0.2% | Mar 6, 2026 | LangBot is a global IM bot platform designed for LLMs. Prior to version 4.8.7, LangBot’s web UI renders user-supplied ra... |
| CVE-2026-28508 | HIGH | 8.6 | 0.6% | Mar 6, 2026 | Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CS... |
| CVE-2026-28507 | HIGH | 7.2 | 0.7% | Mar 6, 2026 | Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained... |
| CVE-2026-28429 | HIGH | 7.5 | 0.7% | Mar 6, 2026 | Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871, a Path Traversal vulnerability was identified i... |
| CVE-2026-28428 | MEDIUM | 5.3 | 0.3% | Mar 6, 2026 | Talishar is a fan-made Flesh and Blood project. Prior to commit a9c218e, an authentication bypass vulnerability in Talis... |
| CVE-2026-27605 | MEDIUM | 5.4 | 0.2% | Mar 6, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-27603 | HIGH | 7.5 | 0.4% | Mar 6, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-27005 | CRITICAL | 9.8 | 0.5% | Mar 6, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-25888 | HIGH | 8.8 | 0.7% | Mar 6, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now