2026 CVE Vulnerabilities

55,528 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-3662HIGH7.2A vulnerability has been found in Wavlink WL-NU516U1 240425. This vulnerability affects the function usb_p910 of the fil...
CVE-2026-3661HIGH7.2A flaw has been found in Wavlink WL-NU516U1 240425. This affects the function ota_new_upgrade of the file /cgi-bin/adm.c...
CVE-2026-2219HIGH7.5It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate t...
CVE-2026-24308HIGH7.5Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an att...
CVE-2026-24281HIGH7.4Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, a...
CVE-2026-1074HIGH7.2The WP App Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app-bar-features' parameter in...
CVE-2026-30840HIGH8.8Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side re...
CVE-2026-30828HIGH7.5Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be ...
CVE-2026-30827HIGH7.5express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to version...
CVE-2026-30823HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there ...
CVE-2026-27796HIGH7.5Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a...
CVE-2026-30822HIGH7.7Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauth...
CVE-2026-30820HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowis...
CVE-2026-30247HIGH7.5WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0....
CVE-2026-3352HIGH7.2The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0...
CVE-2026-2020HIGH7.5The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1...
CVE-2026-25071HIGH7.5XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability i...
CVE-2026-30244HIGH7.5Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate work...
CVE-2026-30242HIGH8.5Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/seri...
CVE-2026-30241HIGH8.2Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDept...
CVE-2026-27137HIGH7.5When verifying a certificate chain which contains a certificate containing multiple email address constraints which shar...
CVE-2026-25679HIGH7.5url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2026-30230HIGH7.5Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1....
CVE-2026-30229HIGH7.2Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-30223HIGH8.8OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentica...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now