2026 CVE Vulnerabilities

45,152 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-32922CRITICAL9.9OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with ...
CVE-2026-32918CRITICAL9.2OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandbox...
CVE-2026-32915CRITICAL9.3OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagen...
CVE-2026-5035CRITICAL9.8A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_wo...
CVE-2026-5034CRITICAL9.8A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of th...
CVE-2026-5033CRITICAL9.8A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functi...
CVE-2026-5030CRITICAL9.8A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHos...
CVE-2026-5020CRITICAL9.8A vulnerability was detected in Totolink A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function setNotice...
CVE-2026-4851CRITICAL9.8GRID::Machine versions through 0.127 for Perl allows arbitrary code execution via unsafe deserialization. GRID::Machine...
CVE-2026-5019CRITICAL9.8A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability...
CVE-2026-5018CRITICAL9.8A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the fil...
CVE-2026-5017CRITICAL9.8A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of t...
CVE-2026-3256CRITICAL9.8HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults ...
CVE-2026-33994CRITICAL9.8Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39...
CVE-2026-33993CRITICAL9.8Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, t...
CVE-2026-33976CRITICAL9.6Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the We...
CVE-2026-33943CRITICAL9.8Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 thro...
CVE-2026-33937CRITICAL9.8Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handleb...
CVE-2026-33896CRITICAL9.1Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ...
CVE-2026-33879CRITICAL9.8Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation...
CVE-2026-33875CRITICAL9.3Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 ar...
CVE-2026-33873CRITICAL9.9Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.0, the Agentic Assis...
CVE-2026-34475CRITICAL9.8Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle UR...
CVE-2026-34205CRITICAL9.6Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (f...
CVE-2026-33765CRITICAL9.8Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now