2026 CVE Vulnerabilities

53,674 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-30852HIGH7.5Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_r...
CVE-2026-30851HIGH8.8Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_a...
CVE-2026-30834HIGH7.5PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7, ...
CVE-2026-29784HIGH8.8Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /sessio...
CVE-2026-29779HIGH7.5UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377...
CVE-2026-29194HIGH8.1Netmaker makes networks with WireGuard. Prior to version 1.5.0, the Authorize middleware in Netmaker incorrectly validat...
CVE-2026-3663HIGH7.1A vulnerability was found in xlnt-community xlnt up to 1.6.1. This issue affects the function xlnt::detail::compound_doc...
CVE-2026-29193HIGH8.2ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login...
CVE-2026-29192HIGH7.7ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login...
CVE-2026-3662HIGH7.2A vulnerability has been found in Wavlink WL-NU516U1 240425. This vulnerability affects the function usb_p910 of the fil...
CVE-2026-3661HIGH7.2A flaw has been found in Wavlink WL-NU516U1 240425. This affects the function ota_new_upgrade of the file /cgi-bin/adm.c...
CVE-2026-2219HIGH7.5It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate t...
CVE-2026-24308HIGH7.5Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an att...
CVE-2026-24281HIGH7.4Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, a...
CVE-2026-1074HIGH7.2The WP App Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app-bar-features' parameter in...
CVE-2026-30840HIGH8.8Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side re...
CVE-2026-30828HIGH7.5Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be ...
CVE-2026-30827HIGH7.5express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to version...
CVE-2026-30823HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there ...
CVE-2026-27796HIGH7.5Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a...
CVE-2026-30822HIGH7.7Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauth...
CVE-2026-30820HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowis...
CVE-2026-30247HIGH7.5WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0....
CVE-2026-3352HIGH7.2The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0...
CVE-2026-2020HIGH7.5The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now