2026 CVE Vulnerabilities
55,528 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3662 | HIGH | 7.2 | 11.2% | Mar 7, 2026 | A vulnerability has been found in Wavlink WL-NU516U1 240425. This vulnerability affects the function usb_p910 of the fil... |
| CVE-2026-3661 | HIGH | 7.2 | 10.9% | Mar 7, 2026 | A flaw has been found in Wavlink WL-NU516U1 240425. This affects the function ota_new_upgrade of the file /cgi-bin/adm.c... |
| CVE-2026-2219 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | It was discovered that dpkg-deb (a component of dpkg, the Debian package management system) does not properly validate t... |
| CVE-2026-24308 | HIGH | 7.5 | 1.2% | Mar 7, 2026 | Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an att... |
| CVE-2026-24281 | HIGH | 7.4 | 0.6% | Mar 7, 2026 | Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, a... |
| CVE-2026-1074 | HIGH | 7.2 | 0.2% | Mar 7, 2026 | The WP App Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app-bar-features' parameter in... |
| CVE-2026-30840 | HIGH | 8.8 | 0.5% | Mar 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side re... |
| CVE-2026-30828 | HIGH | 7.5 | 0.5% | Mar 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be ... |
| CVE-2026-30827 | HIGH | 7.5 | 0.5% | Mar 7, 2026 | express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to version... |
| CVE-2026-30823 | HIGH | 8.8 | 0.4% | Mar 7, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there ... |
| CVE-2026-27796 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a... |
| CVE-2026-30822 | HIGH | 7.7 | 12.9% | Mar 7, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauth... |
| CVE-2026-30820 | HIGH | 8.8 | 0.5% | Mar 7, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowis... |
| CVE-2026-30247 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.... |
| CVE-2026-3352 | HIGH | 7.2 | 0.4% | Mar 7, 2026 | The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0... |
| CVE-2026-2020 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1... |
| CVE-2026-25071 | HIGH | 7.5 | 0.5% | Mar 7, 2026 | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability i... |
| CVE-2026-30244 | HIGH | 7.5 | 0.4% | Mar 6, 2026 | Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate work... |
| CVE-2026-30242 | HIGH | 8.5 | 0.3% | Mar 6, 2026 | Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/seri... |
| CVE-2026-30241 | HIGH | 8.2 | 0.4% | Mar 6, 2026 | Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDept... |
| CVE-2026-27137 | HIGH | 7.5 | 0.6% | Mar 6, 2026 | When verifying a certificate chain which contains a certificate containing multiple email address constraints which shar... |
| CVE-2026-25679 | HIGH | 7.5 | 0.7% | Mar 6, 2026 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. |
| CVE-2026-30230 | HIGH | 7.5 | 0.4% | Mar 6, 2026 | Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1.... |
| CVE-2026-30229 | HIGH | 7.2 | 0.4% | Mar 6, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-30223 | HIGH | 8.8 | 0.3% | Mar 6, 2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentica... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now