2026 CVE Vulnerabilities
45,449 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2330 | CRITICAL | 9.4 | 0.7% | Mar 6, 2026 | An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelis... |
| CVE-2026-29065 | CRITICAL | 9.1 | 0.5% | Mar 6, 2026 | changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerabili... |
| CVE-2026-29058 | CRITICAL | 9.8 | 2.1% | Mar 6, 2026 | AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS ... |
| CVE-2026-29042 | CRITICAL | 9.8 | 2.4% | Mar 6, 2026 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell ... |
| CVE-2026-28802 | CRITICAL | 9.8 | 0.4% | Mar 6, 2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, p... |
| CVE-2026-28795 | CRITICAL | 9.8 | 0.4% | Mar 6, 2026 | OpenChatBI is an intelligent chat-based BI tool powered by large language models, designed to help users query, analyze,... |
| CVE-2026-28438 | CRITICAL | 9.8 | 0.3% | Mar 6, 2026 | CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify t... |
| CVE-2026-2446 | CRITICAL | 9.8 | 0.3% | Mar 6, 2026 | The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action,... |
| CVE-2026-28794 | CRITICAL | 9.8 | 0.9% | Mar 6, 2026 | oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1.... |
| CVE-2026-28787 | CRITICAL | 9 | 0.3% | Mar 6, 2026 | OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authenti... |
| CVE-2026-28785 | CRITICAL | 9.8 | 0.4% | Mar 6, 2026 | Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an at... |
| CVE-2026-28680 | CRITICAL | 9.3 | 0.2% | Mar 6, 2026 | Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual as... |
| CVE-2026-27005 | CRITICAL | 9.8 | 0.5% | Mar 6, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-29093 | CRITICAL | 9.8 | 0.5% | Mar 6, 2026 | WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memca... |
| CVE-2026-28501 | CRITICAL | 9.8 | 1.5% | Mar 6, 2026 | WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exis... |
| CVE-2026-28497 | CRITICAL | 9.1 | 0.5% | Mar 6, 2026 | TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerabil... |
| CVE-2026-28710 | CRITICAL | 9.8 | 0.4% | Mar 6, 2026 | Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: A... |
| CVE-2026-22552 | CRITICAL | 9.8 | 0.9% | Mar 6, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat... |
| CVE-2026-26125 | CRITICAL | 9.8 | 1.2% | Mar 5, 2026 | Payment Orchestrator Service Elevation of Privilege Vulnerability |
| CVE-2026-21536 | CRITICAL | 9.8 | 1.6% | Mar 5, 2026 | Microsoft Devices Pricing Program Remote Code Execution Vulnerability |
| CVE-2026-28479 | CRITICAL | 9.1 | 0.2% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.15 use SHA-1 to hash sandbox identifier cache keys for Docker and browser sandbox conf... |
| CVE-2026-28474 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | OpenClaw's Nextcloud Talk plugin versions prior to 2026.2.6 accept equality matching on the mutable actor.name display n... |
| CVE-2026-28472 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allow... |
| CVE-2026-28470 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allo... |
| CVE-2026-28466 | CRITICAL | 9.9 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal appro... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now