2026 CVE Vulnerabilities
53,674 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25071 | HIGH | 7.5 | 0.5% | Mar 7, 2026 | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability i... |
| CVE-2026-30244 | HIGH | 7.5 | 0.4% | Mar 6, 2026 | Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate work... |
| CVE-2026-30242 | HIGH | 8.5 | 0.3% | Mar 6, 2026 | Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/seri... |
| CVE-2026-30241 | HIGH | 8.2 | 0.4% | Mar 6, 2026 | Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDept... |
| CVE-2026-27137 | HIGH | 7.5 | 0.6% | Mar 6, 2026 | When verifying a certificate chain which contains a certificate containing multiple email address constraints which shar... |
| CVE-2026-25679 | HIGH | 7.5 | 0.7% | Mar 6, 2026 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. |
| CVE-2026-30230 | HIGH | 7.5 | 0.4% | Mar 6, 2026 | Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.... |
| CVE-2026-30229 | HIGH | 7.2 | 0.4% | Mar 6, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-30223 | HIGH | 8.8 | 0.3% | Mar 6, 2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentica... |
| CVE-2026-29795 | HIGH | 7.5 | 0.2% | Mar 6, 2026 | stellar-xdr is a library and CLI containing types and functionality for working with Stellar XDR. Prior to version 25.0.... |
| CVE-2026-29789 | HIGH | 8.8 | 0.4% | Mar 6, 2026 | Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Pri... |
| CVE-2026-29788 | HIGH | 7.5 | 0.3% | Mar 6, 2026 | TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigati... |
| CVE-2026-29182 | HIGH | 7.2 | 0.4% | Mar 6, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-30846 | HIGH | 7.5 | 0.3% | Mar 6, 2026 | Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication e... |
| CVE-2026-30845 | HIGH | 8.2 | 0.3% | Mar 6, 2026 | Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication ... |
| CVE-2026-30844 | HIGH | 8.1 | 0.2% | Mar 6, 2026 | Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forg... |
| CVE-2026-29178 | HIGH | 7.7 | 0.3% | Mar 6, 2026 | Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on a... |
| CVE-2026-29091 | HIGH | 8.1 | 0.8% | Mar 6, 2026 | Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a ... |
| CVE-2026-29089 | HIGH | 8.8 | 0.1% | Mar 6, 2026 | TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From ve... |
| CVE-2026-29087 | HIGH | 7.5 | 0.3% | Mar 6, 2026 | @hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server... |
| CVE-2026-29783 | HIGH | 7.8 | 0.4% | Mar 6, 2026 | The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution thro... |
| CVE-2026-29064 | HIGH | 8.2 | 0.2% | Mar 6, 2026 | Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal... |
| CVE-2026-27764 | HIGH | 8.6 | 0.3% | Mar 6, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ... |
| CVE-2026-26018 | HIGH | 7.5 | 1.1% | Mar 6, 2026 | CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDN... |
| CVE-2026-24696 | HIGH | 8.7 | 0.4% | Mar 6, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now