2026 CVE Vulnerabilities

45,125 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-30306CRITICAL9.8In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute al...
CVE-2026-33026CRITICAL9.1Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism...
CVE-2026-32275CRITICAL9.1Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.1...
CVE-2026-30307CRITICAL9.8Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelis...
CVE-2026-30305CRITICAL9.8Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist s...
CVE-2026-28505CRITICAL10Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() f...
CVE-2026-33032CRITICAL9.8Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context ...
CVE-2026-33030CRITICAL9.9Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Di...
CVE-2026-30562CRITICAL9.3A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-2287CRITICAL9.8CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that...
CVE-2026-2286CRITICAL9.8CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud ser...
CVE-2026-2275CRITICAL9.6The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through ar...
CVE-2026-4415CRITICAL9.8Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is ena...
CVE-2026-4176CRITICAL9.8Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerabl...
CVE-2026-0558CRITICAL9.8A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and proces...
CVE-2026-32987CRITICAL9.8OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/de...
CVE-2026-32975CRITICAL9.8OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable gr...
CVE-2026-32974CRITICAL9.8OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationT...
CVE-2026-32973CRITICAL9.8OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly n...
CVE-2026-32924CRITICAL9.8OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_...
CVE-2026-32922CRITICAL9.9OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with ...
CVE-2026-32918CRITICAL9.2OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandbox...
CVE-2026-32915CRITICAL9.3OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagen...
CVE-2026-5035CRITICAL9.8A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_wo...
CVE-2026-5034CRITICAL9.8A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now