2026 CVE Vulnerabilities
52,241 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30838 | MEDIUM | 6.1 | 0.2% | Mar 7, 2026 | league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by i... |
| CVE-2026-29787 | MEDIUM | 5.3 | 0.4% | Mar 7, 2026 | mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/d... |
| CVE-2026-29786 | MEDIUM | 6.3 | 0.4% | Mar 7, 2026 | node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that p... |
| CVE-2026-29781 | MEDIUM | 6.5 | 0.5% | Mar 7, 2026 | Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vul... |
| CVE-2026-29780 | MEDIUM | 5.5 | 0.2% | Mar 7, 2026 | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well... |
| CVE-2026-29778 | MEDIUM | 6.5 | 0.5% | Mar 7, 2026 | pyLoad is a free and open-source download manager written in Python. From version 0.5.0b3.dev13 to 0.5.0b3.dev96, the ed... |
| CVE-2026-29771 | MEDIUM | 6.5 | 0.3% | Mar 7, 2026 | Netmaker makes networks with WireGuard. Prior to version 1.2.0, the /api/server/shutdown endpoint allows termination of ... |
| CVE-2026-29190 | MEDIUM | 5.3 | 0.4% | Mar 7, 2026 | Karapace is an open-source implementation of Kafka REST and Schema Registry. Prior to version 6.0.0, there is a Path Tra... |
| CVE-2026-29076 | MEDIUM | 5.9 | 0.6% | Mar 7, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib u... |
| CVE-2026-3664 | MEDIUM | 5.5 | 0.2% | Mar 7, 2026 | A vulnerability was determined in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::compound_docum... |
| CVE-2026-29184 | MEDIUM | 6.5 | 0.3% | Mar 7, 2026 | Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template c... |
| CVE-2026-2433 | MEDIUM | 6.1 | 0.2% | Mar 7, 2026 | The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to DOM-Ba... |
| CVE-2026-2420 | MEDIUM | 4.4 | 0.2% | Mar 7, 2026 | The LotekMedia Popup Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in a... |
| CVE-2026-1825 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The Show YouTube video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'syv' shortcod... |
| CVE-2026-1824 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The Infomaniak Connect for OpenID plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'endpoint_lo... |
| CVE-2026-1823 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The Consensus Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's consensus shortco... |
| CVE-2026-1820 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The Media Library Alt Text Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bv... |
| CVE-2026-1805 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The DA Media GigList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's damedia_giglist ... |
| CVE-2026-1574 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The MyQtip – easy qTip2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `myqtip` shor... |
| CVE-2026-1569 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The Wueen plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `wueen-blocket` shortcode i... |
| CVE-2026-1087 | MEDIUM | 4.3 | 0.1% | Mar 7, 2026 | The Guardian News Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2026-1086 | MEDIUM | 4.3 | 0.1% | Mar 7, 2026 | The Font Pairing Preview For Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi... |
| CVE-2026-1085 | MEDIUM | 4.3 | 0.1% | Mar 7, 2026 | The True Ranker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2... |
| CVE-2026-1073 | MEDIUM | 4.3 | 0.1% | Mar 7, 2026 | The Purchase Button For Affiliate Link plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions ... |
| CVE-2026-1071 | MEDIUM | 4.4 | 0.2% | Mar 7, 2026 | The Carta Online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now