2026 CVE Vulnerabilities
53,676 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20882 | HIGH | 8.7 | 0.4% | Mar 6, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc... |
| CVE-2026-20748 | HIGH | 8.6 | 0.3% | Mar 6, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ... |
| CVE-2026-2754 | HIGH | 7.5 | 0.5% | Mar 6, 2026 | Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. ... |
| CVE-2026-2753 | HIGH | 7.5 | 0.5% | Mar 6, 2026 | An Absolute Path Traversal vulnerability exists in Navtor NavBox. The application exposes an HTTP service that fails to ... |
| CVE-2026-3589 | HIGH | 7.5 | 0.1% | Mar 6, 2026 | The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allo... |
| CVE-2026-23925 | HIGH | 8.1 | 0.3% | Mar 6, 2026 | An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configur... |
| CVE-2026-29074 | HIGH | 7.5 | 0.6% | Mar 6, 2026 | SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version ... |
| CVE-2026-29073 | HIGH | 8.8 | 0.3% | Mar 6, 2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directl... |
| CVE-2026-29062 | HIGH | 7.5 | 0.6% | Mar 6, 2026 | jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Pr... |
| CVE-2026-29059 | HIGH | 7.5 | 2.6% | Mar 6, 2026 | Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to vers... |
| CVE-2026-29068 | HIGH | 7.5 | 0.3% | Mar 6, 2026 | PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack b... |
| CVE-2026-29039 | HIGH | 7.5 | 0.5% | Mar 6, 2026 | changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io... |
| CVE-2026-28801 | HIGH | 7.8 | 0.1% | Mar 6, 2026 | Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, any ahk code cont... |
| CVE-2026-28800 | HIGH | 8 | 0.2% | Mar 6, 2026 | Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Disco... |
| CVE-2026-28799 | HIGH | 7.5 | 0.3% | Mar 6, 2026 | PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-f... |
| CVE-2026-28683 | HIGH | 8.7 | 0.2% | Mar 6, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, if... |
| CVE-2026-28681 | HIGH | 8.1 | 0.4% | Mar 6, 2026 | Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From ve... |
| CVE-2026-28679 | HIGH | 7.5 | 0.4% | Mar 6, 2026 | Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0,... |
| CVE-2026-28677 | HIGH | 8.2 | 0.3% | Mar 6, 2026 | OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version... |
| CVE-2026-28676 | HIGH | 8.8 | 0.4% | Mar 6, 2026 | OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version... |
| CVE-2026-28508 | HIGH | 8.6 | 0.6% | Mar 6, 2026 | Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CS... |
| CVE-2026-28507 | HIGH | 7.2 | 0.7% | Mar 6, 2026 | Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained... |
| CVE-2026-28429 | HIGH | 7.5 | 0.7% | Mar 6, 2026 | Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871, a Path Traversal vulnerability was identified i... |
| CVE-2026-27603 | HIGH | 7.5 | 0.4% | Mar 6, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-25888 | HIGH | 8.8 | 0.7% | Mar 6, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now