2026 CVE Vulnerabilities
53,017 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2431 | MEDIUM | 6.1 | 0.2% | Mar 7, 2026 | The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date... |
| CVE-2026-2429 | MEDIUM | 4.9 | 0.3% | Mar 7, 2026 | The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'ce_venue_name' CSV field in the `on_sa... |
| CVE-2026-1902 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The Hammas Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'apix' parameter in the 'h... |
| CVE-2026-1650 | MEDIUM | 5.3 | 0.3% | Mar 7, 2026 | The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to a missing capabili... |
| CVE-2026-25073 | MEDIUM | 5.4 | 0.2% | Mar 7, 2026 | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerabil... |
| CVE-2026-2371 | MEDIUM | 5.3 | 0.3% | Mar 7, 2026 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Insecure Direct Object Referenc... |
| CVE-2026-1981 | MEDIUM | 4.3 | 0.3% | Mar 7, 2026 | The HUMN-1 AI Website Scanner & Human Certification by Winston AI plugin for WordPress is vulnerable to unauthorized mod... |
| CVE-2026-1644 | MEDIUM | 4.3 | 0.2% | Mar 7, 2026 | The WP Frontend Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2026-30238 | MEDIUM | 6.1 | 0.3% | Mar 6, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, a... |
| CVE-2026-30237 | MEDIUM | 6.1 | 0.2% | Mar 6, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, a... |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.3% | Mar 6, 2026 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t... |
| CVE-2026-27138 | MEDIUM | 5.9 | 0.4% | Mar 6, 2026 | Certificate verification can panic when a certificate in the chain has an empty DNS name and another certificate in the ... |
| CVE-2026-30835 | MEDIUM | 5.3 | 0.3% | Mar 6, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-30233 | MEDIUM | 4.3 | 0.4% | Mar 6, 2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authorization fl... |
| CVE-2026-30231 | MEDIUM | 5.3 | 0.3% | Mar 6, 2026 | Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.... |
| CVE-2026-30228 | MEDIUM | 4.9 | 0.3% | Mar 6, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-30227 | MEDIUM | 5.3 | 1.1% | Mar 6, 2026 | MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail ... |
| CVE-2026-30225 | MEDIUM | 4.3 | 0.4% | Mar 6, 2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication c... |
| CVE-2026-30224 | MEDIUM | 5.4 | 0.3% | Mar 6, 2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not r... |
| CVE-2026-29791 | MEDIUM | 6.5 | 0.1% | Mar 6, 2026 | Agentgateway is an open source data plane for agentic AI connectivity within or across any agent framework or environmen... |
| CVE-2026-29790 | MEDIUM | 5.3 | 0.3% | Mar 6, 2026 | dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.3... |
| CVE-2026-30847 | MEDIUM | 6.5 | 0.2% | Mar 6, 2026 | Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publicatio... |
| CVE-2026-30843 | MEDIUM | 6.5 | 0.2% | Mar 6, 2026 | Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Ref... |
| CVE-2026-3419 | MEDIUM | 5.3 | 0.4% | Mar 6, 2026 | Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in ... |
| CVE-2026-30833 | MEDIUM | 5.3 | 0.3% | Mar 6, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.1... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now