2026 CVE Vulnerabilities

45,121 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-34162CRITICAL10FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/...
CVE-2026-33579CRITICAL9.9OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to ...
CVE-2026-30314CRITICAL9.8Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its white...
CVE-2026-30312CRITICAL9.8DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel...
CVE-2026-30311CRITICAL9.8Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its white...
CVE-2026-34156CRITICAL9.9NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-30310CRITICAL9.8In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all ...
CVE-2026-32917CRITICAL9.8OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that...
CVE-2026-32916CRITICAL9.8OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes e...
CVE-2026-4317CRITICAL9.3SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which co...
CVE-2026-5183CRITICAL9.8A vulnerability was determined in TRENDnet TEW-713RE up to 1.02. The affected element is the function sub_421494 of the ...
CVE-2026-34060CRITICAL9.8Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and rub...
CVE-2026-34041CRITICAL9.8act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processe...
CVE-2026-32714CRITICAL9.8SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scito...
CVE-2026-5176CRITICAL9.8A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. Affected is the function setSyslogCfg of ...
CVE-2026-3300CRITICAL9.8The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions...
CVE-2026-30880CRITICAL9.8baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability ...
CVE-2026-27697CRITICAL9.8baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog ...
CVE-2026-4257CRITICAL9.8The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Rem...
CVE-2026-4789CRITICAL9.8Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions.
CVE-2026-34558CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-34557CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-31946CRITICAL9.8OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From vers...
CVE-2026-30313CRITICAL9.8DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel...
CVE-2026-30308CRITICAL9.8In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe comman...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now