2026 CVE Vulnerabilities

66,743 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33579CRITICAL9.9OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to ...
CVE-2026-33578MEDIUM4.3OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where...
CVE-2026-33577HIGH8.6OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that...
CVE-2026-33576MEDIUM6.9OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. ...
CVE-2026-33276MEDIUM5.4Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to c...
CVE-2026-30314CRITICAL9.8Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its white...
CVE-2026-30312CRITICAL9.8DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel...
CVE-2026-30311CRITICAL9.8Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its white...
CVE-2026-30309HIGH7.8InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist ...
CVE-2026-29870HIGH7.6A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file wri...
CVE-2026-20915MEDIUM5.4Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permiss...
CVE-2026-0596HIGH7.8A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_u...
CVE-2026-3308HIGH7.8An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously c...
CVE-2026-34156CRITICAL9.9NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-34155MEDIUM5.3RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' form...
CVE-2026-30310CRITICAL9.8In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all ...
CVE-2026-5198HIGH7.3A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown functi...
CVE-2026-4267HIGH7.2The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site S...
CVE-2026-3191MEDIUM5.4The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2...
CVE-2026-3139MEDIUM4.3The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2026-34509——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-34508——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-34506MEDIUM4.3OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unau...
CVE-2026-34505MEDIUM6.9OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypa...
CVE-2026-32988HIGH7.5OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary fi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now