2026 CVE Vulnerabilities
45,269 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4581 | CRITICAL | 9.8 | 0.4% | Mar 23, 2026 | A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /... |
| CVE-2026-4580 | CRITICAL | 9.8 | 0.3% | Mar 23, 2026 | A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the ... |
| CVE-2026-4579 | CRITICAL | 9.8 | 0.4% | Mar 23, 2026 | A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file ... |
| CVE-2026-3587 | CRITICAL | 10 | 0.7% | Mar 23, 2026 | An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, l... |
| CVE-2026-4601 | CRITICAL | 9.1 | 0.3% | Mar 23, 2026 | Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.sig... |
| CVE-2026-4600 | CRITICAL | 9.1 | 0.2% | Mar 23, 2026 | Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via t... |
| CVE-2026-4599 | CRITICAL | 9.1 | 0.5% | Mar 23, 2026 | Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Fact... |
| CVE-2026-4567 | CRITICAL | 9.8 | 3.7% | Mar 23, 2026 | A vulnerability has been found in Tenda A15 15.13.07.13. The impacted element is the function UploadCfg of the file /cgi... |
| CVE-2026-4606 | CRITICAL | 10 | 0.3% | Mar 23, 2026 | GV Edge Recording Manager (ERM) v2.3.1 improperly runs application components with SYSTEM-level privileges, allowing any... |
| CVE-2026-32064 | CRITICAL | 9.1 | 0.5% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observe... |
| CVE-2026-32056 | CRITICAL | 9.8 | 0.6% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system... |
| CVE-2026-32052 | CRITICAL | 9.8 | 0.9% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allo... |
| CVE-2026-32048 | CRITICAL | 9.9 | 0.3% | Mar 21, 2026 | OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, al... |
| CVE-2026-32046 | CRITICAL | 9.8 | 0.3% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to ex... |
| CVE-2026-32045 | CRITICAL | 9.1 | 0.4% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes,... |
| CVE-2026-24060 | CRITICAL | 9.1 | 0.2% | Mar 21, 2026 | Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted,... |
| CVE-2026-33228 | CRITICAL | 9.8 | 0.8% | Mar 20, 2026 | flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled s... |
| CVE-2026-33210 | CRITICAL | 9.1 | 0.8% | Mar 20, 2026 | Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a fo... |
| CVE-2026-33186 | CRITICAL | 9.1 | 1.6% | Mar 20, 2026 | gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from ... |
| CVE-2026-29796 | CRITICAL | 9.8 | 0.5% | Mar 20, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat... |
| CVE-2026-25192 | CRITICAL | 9.8 | 0.5% | Mar 20, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat... |
| CVE-2026-21732 | CRITICAL | 9.6 | 0.3% | Mar 20, 2026 | A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-... |
| CVE-2026-3584 | CRITICAL | 9.8 | 7.2% | Mar 20, 2026 | The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 v... |
| CVE-2026-4499 | CRITICAL | 9.8 | 3.2% | Mar 20, 2026 | A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Ex... |
| CVE-2026-4497 | CRITICAL | 9.8 | 1.9% | Mar 20, 2026 | A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgrad... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now