2026 CVE Vulnerabilities

64,909 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7315HIGH7.3A flaw has been found in eiceblue spire-pdf-mcp-server 0.1.1. This impacts the function get_pdf_path of the file src/spi...
CVE-2026-7314HIGH7.3A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file ...
CVE-2026-7306MEDIUM5.6A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function o...
CVE-2026-7305MEDIUM6.3A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the fi...
CVE-2026-7303LOW3.7A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xx...
CVE-2026-7297LOW2.4A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function s...
CVE-2026-7296LOW2.4A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the fi...
CVE-2026-41649HIGH7.7Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0...
CVE-2026-41446CRITICAL9.8Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints th...
CVE-2026-37750MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1 allows unauthenticated re...
CVE-2026-33467MEDIUM5.9Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positione...
CVE-2026-7295LOW2.4A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function sa...
CVE-2026-7294LOW2.4A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function sav...
CVE-2026-7293MEDIUM4.7A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function delete_category of...
CVE-2026-7292MEDIUM5.6A security vulnerability has been detected in o2oa up to 10.0. This impacts the function syncFile of the file NodeAgent....
CVE-2026-7291MEDIUM6.3A weakness has been identified in o2oa up to 10.0. This affects the function FileAction of the file FileAction.java of t...
CVE-2026-7290MEDIUM6.3A vulnerability was determined in JeecgBoot up to 3.9.1. Impacted is the function SqlInjectionUtil of the file jeecg-boo...
CVE-2026-6807MEDIUM5.5A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may ...
CVE-2026-6238MEDIUM6.5The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail t...
CVE-2026-5794MEDIUM4.9A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by tri...
CVE-2026-42432HIGH7.8OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect wit...
CVE-2026-42431HIGH8.1OpenClaw before 2026.4.8 contains a security bypass vulnerability in node.invoke(browser.proxy) that allows mutation of ...
CVE-2026-42430MEDIUM6.5OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in Playwright redirect handling that allow...
CVE-2026-42429HIGH7.1OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechani...
CVE-2026-42428HIGH7.5OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now