2026 CVE Vulnerabilities
53,108 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26276 | MEDIUM | 5.4 | 0.2% | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, an attacker can store an HTML/JavaScript payloa... |
| CVE-2026-26196 | MEDIUM | 5.3 | 0.3% | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params lik... |
| CVE-2026-26195 | MEDIUM | 6.1 | 0.2% | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, stored xss is still possible through unsafe tem... |
| CVE-2026-26022 | MEDIUM | 5.4 | 0.3% | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerabili... |
| CVE-2026-30785 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Ins... |
| CVE-2026-26377 | MEDIUM | 5.4 | 0.4% | Mar 5, 2026 | Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the N... |
| CVE-2026-3236 | MEDIUM | 4.3 | 0.2% | Mar 5, 2026 | In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting i... |
| CVE-2026-28551 | MEDIUM | 4.7 | 0.1% | Mar 5, 2026 | Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerabi... |
| CVE-2026-28549 | MEDIUM | 4.7 | 0.1% | Mar 5, 2026 | Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability... |
| CVE-2026-28548 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability m... |
| CVE-2026-28547 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Vulnerability of uninitialized pointer access in the scanning module. Impact: Successful exploitation of this vulnerabil... |
| CVE-2026-28546 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Buffer overflow vulnerability in the scanning module. Impact: Successful exploitation of this vulnerability may affect a... |
| CVE-2026-28542 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Permission bypass vulnerability in the system service framework. Impact: Successful exploitation of this vulnerability m... |
| CVE-2026-2893 | MEDIUM | 6.5 | 0.2% | Mar 5, 2026 | The Page and Post Clone plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' parameter in the content_... |
| CVE-2026-28550 | MEDIUM | 4.7 | 0.1% | Mar 5, 2026 | Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may a... |
| CVE-2026-28545 | MEDIUM | 4.7 | 0.1% | Mar 5, 2026 | Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect av... |
| CVE-2026-28544 | MEDIUM | 4.7 | 0.1% | Mar 5, 2026 | Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect av... |
| CVE-2026-28543 | MEDIUM | 4.7 | 0.1% | Mar 5, 2026 | Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerab... |
| CVE-2026-28541 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may ... |
| CVE-2026-28539 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerabilit... |
| CVE-2026-28538 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability... |
| CVE-2026-28537 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availab... |
| CVE-2026-3072 | MEDIUM | 4.3 | 0.2% | Mar 5, 2026 | The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap... |
| CVE-2026-30777 | MEDIUM | 6.5 | 0.3% | Mar 5, 2026 | EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who ... |
| CVE-2026-29052 | MEDIUM | 6.1 | 0.2% | Mar 5, 2026 | The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and ef... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now