2026 CVE Vulnerabilities
64,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7315 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A flaw has been found in eiceblue spire-pdf-mcp-server 0.1.1. This impacts the function get_pdf_path of the file src/spi... |
| CVE-2026-7314 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file ... |
| CVE-2026-7306 | MEDIUM | 5.6 | 0.3% | Apr 28, 2026 | A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function o... |
| CVE-2026-7305 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the fi... |
| CVE-2026-7303 | LOW | 3.7 | 0.4% | Apr 28, 2026 | A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xx... |
| CVE-2026-7297 | LOW | 2.4 | 0.2% | Apr 28, 2026 | A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function s... |
| CVE-2026-7296 | LOW | 2.4 | 0.2% | Apr 28, 2026 | A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the fi... |
| CVE-2026-41649 | HIGH | 7.7 | 0.3% | Apr 28, 2026 | Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0... |
| CVE-2026-41446 | CRITICAL | 9.8 | 0.4% | Apr 28, 2026 | Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints th... |
| CVE-2026-37750 | MEDIUM | 6.1 | 0.4% | Apr 28, 2026 | A reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1 allows unauthenticated re... |
| CVE-2026-33467 | MEDIUM | 5.9 | 0.1% | Apr 28, 2026 | Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positione... |
| CVE-2026-7295 | LOW | 2.4 | 0.2% | Apr 28, 2026 | A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function sa... |
| CVE-2026-7294 | LOW | 2.4 | 0.2% | Apr 28, 2026 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function sav... |
| CVE-2026-7293 | MEDIUM | 4.7 | 0.2% | Apr 28, 2026 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function delete_category of... |
| CVE-2026-7292 | MEDIUM | 5.6 | 0.3% | Apr 28, 2026 | A security vulnerability has been detected in o2oa up to 10.0. This impacts the function syncFile of the file NodeAgent.... |
| CVE-2026-7291 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A weakness has been identified in o2oa up to 10.0. This affects the function FileAction of the file FileAction.java of t... |
| CVE-2026-7290 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A vulnerability was determined in JeecgBoot up to 3.9.1. Impacted is the function SqlInjectionUtil of the file jeecg-boo... |
| CVE-2026-6807 | MEDIUM | 5.5 | 0.2% | Apr 28, 2026 | A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may ... |
| CVE-2026-6238 | MEDIUM | 6.5 | 0.3% | Apr 28, 2026 | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail t... |
| CVE-2026-5794 | MEDIUM | 4.9 | 0.3% | Apr 28, 2026 | A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by tri... |
| CVE-2026-42432 | HIGH | 7.8 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect wit... |
| CVE-2026-42431 | HIGH | 8.1 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a security bypass vulnerability in node.invoke(browser.proxy) that allows mutation of ... |
| CVE-2026-42430 | MEDIUM | 6.5 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in Playwright redirect handling that allow... |
| CVE-2026-42429 | HIGH | 7.1 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechani... |
| CVE-2026-42428 | HIGH | 7.5 | 0.1% | Apr 28, 2026 | OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can in... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now