2026 CVE Vulnerabilities

65,368 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35620MEDIUM5.4OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handle...
CVE-2026-35619MEDIUM5.3OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to e...
CVE-2026-35602HIGH7.1Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses th...
CVE-2026-35601MEDIUM4.1Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV output generator builds iCale...
CVE-2026-35600MEDIUM5.4Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, task titles are embedded directly into M...
CVE-2026-35599MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function use...
CVE-2026-35598MEDIUM4.3Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesB...
CVE-2026-35597HIGH7.5Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the TOTP failed-attempt lockout mechanis...
CVE-2026-35596MEDIUM4.3Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the hasAccessToLabel function contains a...
CVE-2026-35595HIGH8.3Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/projec...
CVE-2026-22560MEDIUM5.3An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by...
CVE-2026-40228LOW3.3In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p em...
CVE-2026-40227MEDIUM5.5In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that...
CVE-2026-40226MEDIUM6.4In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.
CVE-2026-40225MEDIUM6.4In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel outp...
CVE-2026-40224HIGH7.3In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach ...
CVE-2026-40223MEDIUM5.5In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exi...
CVE-2026-40023MEDIUM5.3Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions...
CVE-2026-40021MEDIUM5.3Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLa...
CVE-2026-35594MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (Get...
CVE-2026-34727CRITICAL9.1Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full ...
CVE-2026-34481HIGH7.5Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions u...
CVE-2026-34480HIGH7.5Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to an...
CVE-2026-34479HIGH7.5The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standa...
CVE-2026-34478HIGH7.5Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now