2026 CVE Vulnerabilities
70,003 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-29059 | HIGH | 7.5 | 2.6% | Mar 6, 2026 | Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to vers... |
| CVE-2026-29068 | HIGH | 7.5 | 0.3% | Mar 6, 2026 | PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack b... |
| CVE-2026-29065 | CRITICAL | 9.1 | 0.5% | Mar 6, 2026 | changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerabili... |
| CVE-2026-29058 | CRITICAL | 9.8 | 2.1% | Mar 6, 2026 | AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS ... |
| CVE-2026-29049 | MEDIUM | 4.3 | 0.2% | Mar 6, 2026 | melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cach... |
| CVE-2026-29048 | MEDIUM | 6.1 | 0.2% | Mar 6, 2026 | HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identifi... |
| CVE-2026-29042 | CRITICAL | 9.8 | 2.4% | Mar 6, 2026 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell ... |
| CVE-2026-29039 | HIGH | 7.5 | 0.5% | Mar 6, 2026 | changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io... |
| CVE-2026-29038 | MEDIUM | 6.1 | 0.3% | Mar 6, 2026 | changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, there is a reflected c... |
| CVE-2026-28804 | MEDIUM | 5.3 | 0.4% | Mar 6, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability... |
| CVE-2026-28802 | CRITICAL | 9.8 | 0.4% | Mar 6, 2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, p... |
| CVE-2026-28801 | HIGH | 7.8 | 0.1% | Mar 6, 2026 | Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, any ahk code cont... |
| CVE-2026-28800 | HIGH | 8 | 0.2% | Mar 6, 2026 | Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Disco... |
| CVE-2026-28799 | HIGH | 7.5 | 0.3% | Mar 6, 2026 | PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-f... |
| CVE-2026-28795 | CRITICAL | 9.8 | 0.4% | Mar 6, 2026 | OpenChatBI is an intelligent chat-based BI tool powered by large language models, designed to help users query, analyze,... |
| CVE-2026-28438 | CRITICAL | 9.8 | 0.3% | Mar 6, 2026 | CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify t... |
| CVE-2026-2446 | CRITICAL | 9.8 | 0.3% | Mar 6, 2026 | The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action,... |
| CVE-2026-1128 | MEDIUM | 4.3 | 0.1% | Mar 6, 2026 | The WP eCommerce WordPress plugin through 3.15.1 does not have CSRF check in place when deleting coupons, which could al... |
| CVE-2026-29084 | MEDIUM | 4.6 | 0.1% | Mar 6, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th... |
| CVE-2026-29061 | MEDIUM | 5.4 | 0.1% | Mar 6, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a ... |
| CVE-2026-29060 | MEDIUM | 5 | 0.1% | Mar 6, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a ... |
| CVE-2026-28794 | CRITICAL | 9.8 | 0.9% | Mar 6, 2026 | oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.... |
| CVE-2026-28787 | CRITICAL | 9 | 0.3% | Mar 6, 2026 | OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authenti... |
| CVE-2026-28785 | CRITICAL | 9.8 | 0.4% | Mar 6, 2026 | Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an at... |
| CVE-2026-28685 | MEDIUM | 6.5 | 0.4% | Mar 6, 2026 | Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now