2026 CVE Vulnerabilities
45,151 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34558 | CRITICAL | 9 | 0.3% | Mar 30, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-34557 | CRITICAL | 9 | 0.3% | Mar 30, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-31946 | CRITICAL | 9.8 | 0.2% | Mar 30, 2026 | OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From vers... |
| CVE-2026-30313 | CRITICAL | 9.8 | 1.1% | Mar 30, 2026 | DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel... |
| CVE-2026-30308 | CRITICAL | 9.8 | 0.5% | Mar 30, 2026 | In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe comman... |
| CVE-2026-30306 | CRITICAL | 9.8 | 0.7% | Mar 30, 2026 | In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute al... |
| CVE-2026-33026 | CRITICAL | 9.1 | 0.3% | Mar 30, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism... |
| CVE-2026-32275 | CRITICAL | 9.1 | 0.3% | Mar 30, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.1... |
| CVE-2026-30307 | CRITICAL | 9.8 | 1.1% | Mar 30, 2026 | Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelis... |
| CVE-2026-30305 | CRITICAL | 9.8 | 1.1% | Mar 30, 2026 | Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist s... |
| CVE-2026-28505 | CRITICAL | 10 | 0.5% | Mar 30, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() f... |
| CVE-2026-33032 | CRITICAL | 9.8 | 38.5% | Mar 30, 2026 | Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context ... |
| CVE-2026-33030 | CRITICAL | 9.9 | 0.3% | Mar 30, 2026 | Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Di... |
| CVE-2026-30562 | CRITICAL | 9.3 | 0.3% | Mar 30, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner... |
| CVE-2026-2287 | CRITICAL | 9.8 | 0.7% | Mar 30, 2026 | CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that... |
| CVE-2026-2286 | CRITICAL | 9.8 | 0.5% | Mar 30, 2026 | CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud ser... |
| CVE-2026-2275 | CRITICAL | 9.6 | 0.4% | Mar 30, 2026 | The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through ar... |
| CVE-2026-4415 | CRITICAL | 9.8 | 0.7% | Mar 30, 2026 | Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is ena... |
| CVE-2026-4176 | CRITICAL | 9.8 | 0.7% | Mar 29, 2026 | Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerabl... |
| CVE-2026-0558 | CRITICAL | 9.8 | 0.4% | Mar 29, 2026 | A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and proces... |
| CVE-2026-32987 | CRITICAL | 9.8 | 0.4% | Mar 29, 2026 | OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/de... |
| CVE-2026-32975 | CRITICAL | 9.8 | 0.3% | Mar 29, 2026 | OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable gr... |
| CVE-2026-32974 | CRITICAL | 9.8 | 0.2% | Mar 29, 2026 | OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationT... |
| CVE-2026-32973 | CRITICAL | 9.8 | 0.4% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly n... |
| CVE-2026-32924 | CRITICAL | 9.8 | 0.3% | Mar 29, 2026 | OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now