2026 CVE Vulnerabilities

62,186 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45628CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands ...
CVE-2026-45627HIGH8.2Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticat...
CVE-2026-45626MEDIUM6.3Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /enviro...
CVE-2026-45625CRITICAL9.9Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-bas...
CVE-2026-45577MEDIUM6.9Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public...
CVE-2026-44697HIGH8.6Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-...
CVE-2026-43917MEDIUM5.3Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and earlier, the protectedProcedure middleware ...
CVE-2026-10108HIGH8.7xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint th...
CVE-2026-10107HIGH7.7MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated...
CVE-2026-10105HIGH8.7agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inj...
CVE-2026-10070MEDIUM5.1A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of...
CVE-2026-9194Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-48501CRITICAL9.1GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization h...
CVE-2026-45663CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability ...
CVE-2026-45662HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dok...
CVE-2026-44962CRITICAL9.9Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied...
CVE-2026-39276HIGH7.2The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrator...
CVE-2026-39229MEDIUM6.5Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated atta...
CVE-2026-36324MEDIUM6.1SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of use...
CVE-2026-35674HIGH8.8OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped client...
CVE-2026-35673MEDIUM6.5OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows re...
CVE-2026-35630HIGH8OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to ...
CVE-2026-34507MEDIUM5.4OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated sende...
CVE-2026-33386LOW2.3QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malici...
CVE-2026-33384MEDIUM4.8QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now