2026 CVE Vulnerabilities

45,151 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-34558CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-34557CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-31946CRITICAL9.8OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From vers...
CVE-2026-30313CRITICAL9.8DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel...
CVE-2026-30308CRITICAL9.8In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe comman...
CVE-2026-30306CRITICAL9.8In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute al...
CVE-2026-33026CRITICAL9.1Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism...
CVE-2026-32275CRITICAL9.1Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.1...
CVE-2026-30307CRITICAL9.8Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelis...
CVE-2026-30305CRITICAL9.8Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist s...
CVE-2026-28505CRITICAL10Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() f...
CVE-2026-33032CRITICAL9.8Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context ...
CVE-2026-33030CRITICAL9.9Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Di...
CVE-2026-30562CRITICAL9.3A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-2287CRITICAL9.8CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that...
CVE-2026-2286CRITICAL9.8CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud ser...
CVE-2026-2275CRITICAL9.6The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through ar...
CVE-2026-4415CRITICAL9.8Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is ena...
CVE-2026-4176CRITICAL9.8Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerabl...
CVE-2026-0558CRITICAL9.8A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and proces...
CVE-2026-32987CRITICAL9.8OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/de...
CVE-2026-32975CRITICAL9.8OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable gr...
CVE-2026-32974CRITICAL9.8OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationT...
CVE-2026-32973CRITICAL9.8OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly n...
CVE-2026-32924CRITICAL9.8OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now