2026 CVE Vulnerabilities

45,141 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-34221CRITICAL9.1MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions...
CVE-2026-34220CRITICAL9.8MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions...
CVE-2026-30281CRITICAL9.8An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files ...
CVE-2026-30276CRITICAL9.8An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical in...
CVE-2026-34532CRITICAL9.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34162CRITICAL10FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/...
CVE-2026-33579CRITICAL9.9OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to ...
CVE-2026-30314CRITICAL9.8Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its white...
CVE-2026-30312CRITICAL9.8DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel...
CVE-2026-30311CRITICAL9.8Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its white...
CVE-2026-34156CRITICAL9.9NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-30310CRITICAL9.8In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all ...
CVE-2026-32917CRITICAL9.8OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that...
CVE-2026-32916CRITICAL9.8OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes e...
CVE-2026-4317CRITICAL9.3SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which co...
CVE-2026-5183CRITICAL9.8A vulnerability was determined in TRENDnet TEW-713RE up to 1.02. The affected element is the function sub_421494 of the ...
CVE-2026-34060CRITICAL9.8Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and rub...
CVE-2026-34041CRITICAL9.8act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processe...
CVE-2026-32714CRITICAL9.8SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scito...
CVE-2026-5176CRITICAL9.8A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. Affected is the function setSyslogCfg of ...
CVE-2026-3300CRITICAL9.8The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions...
CVE-2026-30880CRITICAL9.8baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability ...
CVE-2026-27697CRITICAL9.8baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog ...
CVE-2026-4257CRITICAL9.8The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Rem...
CVE-2026-4789CRITICAL9.8Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now