2026 CVE Vulnerabilities

45,449 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-2330CRITICAL9.4An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelis...
CVE-2026-29065CRITICAL9.1changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerabili...
CVE-2026-29058CRITICAL9.8AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS ...
CVE-2026-29042CRITICAL9.8Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell ...
CVE-2026-28802CRITICAL9.8Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, p...
CVE-2026-28795CRITICAL9.8OpenChatBI is an intelligent chat-based BI tool powered by large language models, designed to help users query, analyze,...
CVE-2026-28438CRITICAL9.8CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify t...
CVE-2026-2446CRITICAL9.8The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action,...
CVE-2026-28794CRITICAL9.8oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1....
CVE-2026-28787CRITICAL9OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authenti...
CVE-2026-28785CRITICAL9.8Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an at...
CVE-2026-28680CRITICAL9.3Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual as...
CVE-2026-27005CRITICAL9.8Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-29093CRITICAL9.8WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memca...
CVE-2026-28501CRITICAL9.8WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exis...
CVE-2026-28497CRITICAL9.1TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerabil...
CVE-2026-28710CRITICAL9.8Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: A...
CVE-2026-22552CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat...
CVE-2026-26125CRITICAL9.8Payment Orchestrator Service Elevation of Privilege Vulnerability
CVE-2026-21536CRITICAL9.8Microsoft Devices Pricing Program Remote Code Execution Vulnerability
CVE-2026-28479CRITICAL9.1OpenClaw versions prior to 2026.2.15 use SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox conf...
CVE-2026-28474CRITICAL9.8OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display n...
CVE-2026-28472CRITICAL9.8OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allow...
CVE-2026-28470CRITICAL9.8OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allo...
CVE-2026-28466CRITICAL9.9OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal appro...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now