2026 CVE Vulnerabilities
52,730 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3681 | MEDIUM | 6.3 | 0.2% | Mar 7, 2026 | A weakness has been identified in welovemedia FFmate up to 2.0.15. This affects the function fireWebhook of the file /in... |
| CVE-2026-3680 | MEDIUM | 6.3 | 1.1% | Mar 7, 2026 | A security flaw has been discovered in RyuzakiShinji biome-mcp-server up to 1.0.0. Affected by this issue is some unknow... |
| CVE-2026-3675 | MEDIUM | 5.3 | 0.1% | Mar 7, 2026 | A vulnerability was determined in Freedom Factory dGEN1 up to 20260221. Affected by this issue is the function FakeAppRe... |
| CVE-2026-3674 | MEDIUM | 5.3 | 0.1% | Mar 7, 2026 | A vulnerability was found in Freedom Factory dGEN1 up to 20260221. Affected by this vulnerability is the function FakeAp... |
| CVE-2026-3672 | MEDIUM | 6.3 | 0.2% | Mar 7, 2026 | A vulnerability has been found in JeecgBoot up to 3.9.1. Affected is the function isExistSqlInjectKeyword of the file /j... |
| CVE-2026-3670 | MEDIUM | 5.3 | 0.1% | Mar 7, 2026 | A vulnerability was detected in Freedom Factory dGEN1 up to 20260221. Affected is an unknown function of the component c... |
| CVE-2026-3669 | MEDIUM | 5.3 | 0.1% | Mar 7, 2026 | A security vulnerability has been detected in Freedom Factory dGEN1 up to 20260221. This impacts the function AlarmServi... |
| CVE-2026-30859 | MEDIUM | 6.5 | 0.2% | Mar 7, 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.... |
| CVE-2026-30857 | MEDIUM | 5.3 | 0.2% | Mar 7, 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.... |
| CVE-2026-30854 | MEDIUM | 5.3 | 0.3% | Mar 7, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.3... |
| CVE-2026-30850 | MEDIUM | 5.9 | 0.3% | Mar 7, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-29196 | MEDIUM | 4.3 | 0.3% | Mar 7, 2026 | Netmaker makes networks with WireGuard. Prior to version 1.5.0, a user assigned the platform-user role can retrieve Wire... |
| CVE-2026-29195 | MEDIUM | 6.5 | 0.2% | Mar 7, 2026 | Netmaker makes networks with WireGuard. Prior to version 1.5.0, the user update handler (PUT /api/users/{username}) lack... |
| CVE-2026-3667 | MEDIUM | 5.3 | 0.1% | Mar 7, 2026 | A security flaw has been discovered in Freedom Factory dGEN1 up to 20260221. The impacted element is the function FakeAp... |
| CVE-2026-3665 | MEDIUM | 5.5 | 0.2% | Mar 7, 2026 | A vulnerability was identified in xlnt-community xlnt up to 1.6.1. The affected element is the function xlnt::detail::xl... |
| CVE-2026-30838 | MEDIUM | 6.1 | 0.2% | Mar 7, 2026 | league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by i... |
| CVE-2026-29787 | MEDIUM | 5.3 | 0.4% | Mar 7, 2026 | mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/d... |
| CVE-2026-29786 | MEDIUM | 6.3 | 0.4% | Mar 7, 2026 | node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that p... |
| CVE-2026-29781 | MEDIUM | 6.5 | 0.5% | Mar 7, 2026 | Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vul... |
| CVE-2026-29780 | MEDIUM | 5.5 | 0.2% | Mar 7, 2026 | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well... |
| CVE-2026-29778 | MEDIUM | 6.5 | 0.5% | Mar 7, 2026 | pyLoad is a free and open-source download manager written in Python. From version 0.5.0b3.dev13 to 0.5.0b3.dev96, the ed... |
| CVE-2026-29771 | MEDIUM | 6.5 | 0.3% | Mar 7, 2026 | Netmaker makes networks with WireGuard. Prior to version 1.2.0, the /api/server/shutdown endpoint allows termination of ... |
| CVE-2026-29190 | MEDIUM | 5.3 | 0.4% | Mar 7, 2026 | Karapace is an open-source implementation of Kafka REST and Schema Registry. Prior to version 6.0.0, there is a Path Tra... |
| CVE-2026-29076 | MEDIUM | 5.9 | 0.6% | Mar 7, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib u... |
| CVE-2026-3664 | MEDIUM | 5.5 | 0.2% | Mar 7, 2026 | A vulnerability was determined in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::compound_docum... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now