2026 CVE Vulnerabilities

63,579 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-10108HIGH8.7xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint th...
CVE-2026-10107HIGH7.7MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated...
CVE-2026-10105HIGH8.7agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inj...
CVE-2026-10070MEDIUM5.1A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of...
CVE-2026-9194——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-48501CRITICAL9.1GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization h...
CVE-2026-45663CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability ...
CVE-2026-45662HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dok...
CVE-2026-44962CRITICAL9.9Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied...
CVE-2026-39276HIGH7.2The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrator...
CVE-2026-39229MEDIUM6.5Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated atta...
CVE-2026-36324MEDIUM6.1SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of use...
CVE-2026-35674HIGH8.8OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped client...
CVE-2026-35673MEDIUM6.5OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows re...
CVE-2026-35630HIGH8OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to ...
CVE-2026-34507MEDIUM5.4OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated sende...
CVE-2026-33386LOW2.3QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malici...
CVE-2026-33384MEDIUM4.8QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same...
CVE-2026-32906MEDIUM4.3OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-autho...
CVE-2026-32905HIGH8.7OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows no...
CVE-2026-10101MEDIUM6.3ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pul...
CVE-2026-10099MEDIUM5.1XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_s...
CVE-2026-10069HIGH8.7A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of the file usr/sbin/m...
CVE-2026-10068HIGH7.3A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of...
CVE-2026-10067HIGH8.8A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The mani...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now