2026 CVE Vulnerabilities
62,186 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45628 | CRITICAL | 9.6 | 0.2% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands ... |
| CVE-2026-45627 | HIGH | 8.2 | 0.2% | May 29, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticat... |
| CVE-2026-45626 | MEDIUM | 6.3 | 0.2% | May 29, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /enviro... |
| CVE-2026-45625 | CRITICAL | 9.9 | 0.4% | May 29, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-bas... |
| CVE-2026-45577 | MEDIUM | 6.9 | 0.2% | May 29, 2026 | Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public... |
| CVE-2026-44697 | HIGH | 8.6 | 0.4% | May 29, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-... |
| CVE-2026-43917 | MEDIUM | 5.3 | 0.2% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and earlier, the protectedProcedure middleware ... |
| CVE-2026-10108 | HIGH | 8.7 | 0.5% | May 29, 2026 | xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint th... |
| CVE-2026-10107 | HIGH | 7.7 | 0.3% | May 29, 2026 | MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated... |
| CVE-2026-10105 | HIGH | 8.7 | 0.3% | May 29, 2026 | agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inj... |
| CVE-2026-10070 | MEDIUM | 5.1 | 0.2% | May 29, 2026 | A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of... |
| CVE-2026-9194 | — | — | — | May 29, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-48501 | CRITICAL | 9.1 | 0.3% | May 29, 2026 | GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization h... |
| CVE-2026-45663 | CRITICAL | 9.9 | 0.9% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability ... |
| CVE-2026-45662 | HIGH | 8.8 | 0.8% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dok... |
| CVE-2026-44962 | CRITICAL | 9.9 | 0.7% | May 29, 2026 | Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied... |
| CVE-2026-39276 | HIGH | 7.2 | 0.8% | May 29, 2026 | The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrator... |
| CVE-2026-39229 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated atta... |
| CVE-2026-36324 | MEDIUM | 6.1 | 0.2% | May 29, 2026 | SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of use... |
| CVE-2026-35674 | HIGH | 8.8 | 0.3% | May 29, 2026 | OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped client... |
| CVE-2026-35673 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows re... |
| CVE-2026-35630 | HIGH | 8 | 0.2% | May 29, 2026 | OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to ... |
| CVE-2026-34507 | MEDIUM | 5.4 | 0.1% | May 29, 2026 | OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated sende... |
| CVE-2026-33386 | LOW | 2.3 | 0.2% | May 29, 2026 | QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malici... |
| CVE-2026-33384 | MEDIUM | 4.8 | 0.2% | May 29, 2026 | QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now