2026 CVE Vulnerabilities
45,141 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34221 | CRITICAL | 9.1 | 0.4% | Mar 31, 2026 | MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions... |
| CVE-2026-34220 | CRITICAL | 9.8 | 0.4% | Mar 31, 2026 | MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions... |
| CVE-2026-30281 | CRITICAL | 9.8 | 0.7% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files ... |
| CVE-2026-30276 | CRITICAL | 9.8 | 0.7% | Mar 31, 2026 | An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical in... |
| CVE-2026-34532 | CRITICAL | 9.1 | 0.3% | Mar 31, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-34162 | CRITICAL | 10 | 0.4% | Mar 31, 2026 | FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/... |
| CVE-2026-33579 | CRITICAL | 9.9 | 0.6% | Mar 31, 2026 | OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to ... |
| CVE-2026-30314 | CRITICAL | 9.8 | 1.2% | Mar 31, 2026 | Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its white... |
| CVE-2026-30312 | CRITICAL | 9.8 | 1.7% | Mar 31, 2026 | DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel... |
| CVE-2026-30311 | CRITICAL | 9.8 | 1.7% | Mar 31, 2026 | Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its white... |
| CVE-2026-34156 | CRITICAL | 9.9 | 36.5% | Mar 31, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-30310 | CRITICAL | 9.8 | 0.5% | Mar 31, 2026 | In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all ... |
| CVE-2026-32917 | CRITICAL | 9.8 | 2.0% | Mar 31, 2026 | OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that... |
| CVE-2026-32916 | CRITICAL | 9.8 | 0.5% | Mar 31, 2026 | OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes e... |
| CVE-2026-4317 | CRITICAL | 9.3 | 0.3% | Mar 31, 2026 | SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which co... |
| CVE-2026-5183 | CRITICAL | 9.8 | 5.1% | Mar 31, 2026 | A vulnerability was determined in TRENDnet TEW-713RE up to 1.02. The affected element is the function sub_421494 of the ... |
| CVE-2026-34060 | CRITICAL | 9.8 | 0.5% | Mar 31, 2026 | Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and rub... |
| CVE-2026-34041 | CRITICAL | 9.8 | 0.6% | Mar 31, 2026 | act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processe... |
| CVE-2026-32714 | CRITICAL | 9.8 | 0.5% | Mar 31, 2026 | SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scito... |
| CVE-2026-5176 | CRITICAL | 9.8 | 1.9% | Mar 31, 2026 | A security flaw has been discovered in Totolink A3300R 17.0.0cu.557_b20221024. Affected is the function setSyslogCfg of ... |
| CVE-2026-3300 | CRITICAL | 9.8 | 41.0% | Mar 31, 2026 | The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions... |
| CVE-2026-30880 | CRITICAL | 9.8 | 2.1% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has an OS command injection vulnerability ... |
| CVE-2026-27697 | CRITICAL | 9.8 | 0.4% | Mar 31, 2026 | baserCMS is a website development framework. Prior to version 5.2.3, baserCMS has a SQL injection vulnerability in blog ... |
| CVE-2026-4257 | CRITICAL | 9.8 | 41.5% | Mar 30, 2026 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Rem... |
| CVE-2026-4789 | CRITICAL | 9.8 | 0.7% | Mar 30, 2026 | Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now