2026 CVE Vulnerabilities
53,674 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30852 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | Caddy is an extensible server platform that uses TLS by default. From version 2.7.5 to before version 2.11.2, the vars_r... |
| CVE-2026-30851 | HIGH | 8.8 | 0.2% | Mar 7, 2026 | Caddy is an extensible server platform that uses TLS by default. From version 2.10.0 to before version 2.11.2, forward_a... |
| CVE-2026-30834 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7, ... |
| CVE-2026-29784 | HIGH | 8.8 | 0.2% | Mar 7, 2026 | Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /sessio... |
| CVE-2026-29779 | HIGH | 7.5 | 0.3% | Mar 7, 2026 | UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377... |
| CVE-2026-29194 | HIGH | 8.1 | 0.4% | Mar 7, 2026 | Netmaker makes networks with WireGuard. Prior to version 1.5.0, the Authorize middleware in Netmaker incorrectly validat... |
| CVE-2026-3663 | HIGH | 7.1 | 0.2% | Mar 7, 2026 | A vulnerability was found in xlnt-community xlnt up to 1.6.1. This issue affects the function xlnt::detail::compound_doc... |
| CVE-2026-29193 | HIGH | 8.2 | 0.3% | Mar 7, 2026 | ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login... |
| CVE-2026-29192 | HIGH | 7.7 | 0.3% | Mar 7, 2026 | ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login... |
| CVE-2026-3662 | HIGH | 7.2 | 11.2% | Mar 7, 2026 | A vulnerability has been found in Wavlink WL-NU516U1 240425. This vulnerability affects the function usb_p910 of the fil... |
| CVE-2026-3661 | HIGH | 7.2 | 10.9% | Mar 7, 2026 | A flaw has been found in Wavlink WL-NU516U1 240425. This affects the function ota_new_upgrade of the file /cgi-bin/adm.c... |
| CVE-2026-2219 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate t... |
| CVE-2026-24308 | HIGH | 7.5 | 1.2% | Mar 7, 2026 | Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an att... |
| CVE-2026-24281 | HIGH | 7.4 | 0.6% | Mar 7, 2026 | Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, a... |
| CVE-2026-1074 | HIGH | 7.2 | 0.2% | Mar 7, 2026 | The WP App Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app-bar-features' parameter in... |
| CVE-2026-30840 | HIGH | 8.8 | 0.5% | Mar 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side re... |
| CVE-2026-30828 | HIGH | 7.5 | 0.5% | Mar 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be ... |
| CVE-2026-30827 | HIGH | 7.5 | 0.5% | Mar 7, 2026 | express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to version... |
| CVE-2026-30823 | HIGH | 8.8 | 0.4% | Mar 7, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there ... |
| CVE-2026-27796 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a... |
| CVE-2026-30822 | HIGH | 7.7 | 12.9% | Mar 7, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauth... |
| CVE-2026-30820 | HIGH | 8.8 | 0.5% | Mar 7, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowis... |
| CVE-2026-30247 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.... |
| CVE-2026-3352 | HIGH | 7.2 | 0.4% | Mar 7, 2026 | The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0... |
| CVE-2026-2020 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now