2026 CVE Vulnerabilities

45,269 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-4581CRITICAL9.8A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /...
CVE-2026-4580CRITICAL9.8A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the ...
CVE-2026-4579CRITICAL9.8A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file ...
CVE-2026-3587CRITICAL10An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, l...
CVE-2026-4601CRITICAL9.1Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.sig...
CVE-2026-4600CRITICAL9.1Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via t...
CVE-2026-4599CRITICAL9.1Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Fact...
CVE-2026-4567CRITICAL9.8A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi...
CVE-2026-4606CRITICAL10GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any...
CVE-2026-32064CRITICAL9.1OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observe...
CVE-2026-32056CRITICAL9.8OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system...
CVE-2026-32052CRITICAL9.8OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allo...
CVE-2026-32048CRITICAL9.9OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, al...
CVE-2026-32046CRITICAL9.8OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to ex...
CVE-2026-32045CRITICAL9.1OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes,...
CVE-2026-24060CRITICAL9.1Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted,...
CVE-2026-33228CRITICAL9.8flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled s...
CVE-2026-33210CRITICAL9.1Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a fo...
CVE-2026-33186CRITICAL9.1gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from ...
CVE-2026-29796CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat...
CVE-2026-25192CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat...
CVE-2026-21732CRITICAL9.6A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-...
CVE-2026-3584CRITICAL9.8The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 v...
CVE-2026-4499CRITICAL9.8A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Ex...
CVE-2026-4497CRITICAL9.8A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgrad...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now