2026 CVE Vulnerabilities
45,152 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32922 | CRITICAL | 9.9 | 0.5% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with ... |
| CVE-2026-32918 | CRITICAL | 9.2 | 0.1% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandbox... |
| CVE-2026-32915 | CRITICAL | 9.3 | 0.1% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagen... |
| CVE-2026-5035 | CRITICAL | 9.8 | 0.4% | Mar 29, 2026 | A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_wo... |
| CVE-2026-5034 | CRITICAL | 9.8 | 0.3% | Mar 29, 2026 | A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of th... |
| CVE-2026-5033 | CRITICAL | 9.8 | 0.3% | Mar 29, 2026 | A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functi... |
| CVE-2026-5030 | CRITICAL | 9.8 | 2.3% | Mar 29, 2026 | A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHos... |
| CVE-2026-5020 | CRITICAL | 9.8 | 2.2% | Mar 29, 2026 | A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNotice... |
| CVE-2026-4851 | CRITICAL | 9.8 | 0.5% | Mar 29, 2026 | GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine... |
| CVE-2026-5019 | CRITICAL | 9.8 | 0.4% | Mar 29, 2026 | A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability... |
| CVE-2026-5018 | CRITICAL | 9.8 | 0.3% | Mar 28, 2026 | A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the fil... |
| CVE-2026-5017 | CRITICAL | 9.8 | 0.3% | Mar 28, 2026 | A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of t... |
| CVE-2026-3256 | CRITICAL | 9.8 | 0.5% | Mar 28, 2026 | HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults ... |
| CVE-2026-33994 | CRITICAL | 9.8 | 0.6% | Mar 27, 2026 | Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39... |
| CVE-2026-33993 | CRITICAL | 9.8 | 0.6% | Mar 27, 2026 | Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, t... |
| CVE-2026-33976 | CRITICAL | 9.6 | 0.7% | Mar 27, 2026 | Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the We... |
| CVE-2026-33943 | CRITICAL | 9.8 | 0.8% | Mar 27, 2026 | Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 thro... |
| CVE-2026-33937 | CRITICAL | 9.8 | 1.8% | Mar 27, 2026 | Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handleb... |
| CVE-2026-33896 | CRITICAL | 9.1 | 0.3% | Mar 27, 2026 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ... |
| CVE-2026-33879 | CRITICAL | 9.8 | 0.3% | Mar 27, 2026 | Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation... |
| CVE-2026-33875 | CRITICAL | 9.3 | 0.3% | Mar 27, 2026 | Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 ar... |
| CVE-2026-33873 | CRITICAL | 9.9 | 1.4% | Mar 27, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assis... |
| CVE-2026-34475 | CRITICAL | 9.8 | 0.2% | Mar 27, 2026 | Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle UR... |
| CVE-2026-34205 | CRITICAL | 9.6 | 0.3% | Mar 27, 2026 | Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (f... |
| CVE-2026-33765 | CRITICAL | 9.8 | 1.1% | Mar 27, 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now