2026 CVE Vulnerabilities
66,764 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33276 | MEDIUM | 5.4 | 0.1% | Mar 31, 2026 | Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to c... |
| CVE-2026-30314 | CRITICAL | 9.8 | 1.2% | Mar 31, 2026 | Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its white... |
| CVE-2026-30312 | CRITICAL | 9.8 | 1.7% | Mar 31, 2026 | DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel... |
| CVE-2026-30311 | CRITICAL | 9.8 | 1.7% | Mar 31, 2026 | Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its white... |
| CVE-2026-30309 | HIGH | 7.8 | 0.3% | Mar 31, 2026 | InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist ... |
| CVE-2026-29870 | HIGH | 7.6 | 0.6% | Mar 31, 2026 | A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file wri... |
| CVE-2026-20915 | MEDIUM | 5.4 | 0.1% | Mar 31, 2026 | Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permiss... |
| CVE-2026-0596 | HIGH | 7.8 | 1.3% | Mar 31, 2026 | A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_u... |
| CVE-2026-3308 | HIGH | 7.8 | 0.2% | Mar 31, 2026 | An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously c... |
| CVE-2026-34156 | CRITICAL | 9.9 | 36.5% | Mar 31, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-34155 | MEDIUM | 5.3 | 0.1% | Mar 31, 2026 | RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' form... |
| CVE-2026-30310 | CRITICAL | 9.8 | 0.5% | Mar 31, 2026 | In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all ... |
| CVE-2026-5198 | HIGH | 7.3 | 0.3% | Mar 31, 2026 | A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown functi... |
| CVE-2026-4267 | HIGH | 7.2 | 0.3% | Mar 31, 2026 | The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site S... |
| CVE-2026-3191 | MEDIUM | 5.4 | 0.2% | Mar 31, 2026 | The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2... |
| CVE-2026-3139 | MEDIUM | 4.3 | 0.2% | Mar 31, 2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2026-34509 | — | — | — | Mar 31, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-34508 | — | — | — | Mar 31, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-34506 | MEDIUM | 4.3 | 0.3% | Mar 31, 2026 | OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unau... |
| CVE-2026-34505 | MEDIUM | 6.9 | 0.3% | Mar 31, 2026 | OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypa... |
| CVE-2026-32988 | HIGH | 7.5 | 0.1% | Mar 31, 2026 | OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary fi... |
| CVE-2026-32982 | HIGH | 8.7 | 0.4% | Mar 31, 2026 | OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes... |
| CVE-2026-32977 | MEDIUM | 6.3 | 0.1% | Mar 31, 2026 | OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that u... |
| CVE-2026-32976 | HIGH | 7.1 | 0.2% | Mar 31, 2026 | OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected s... |
| CVE-2026-32971 | HIGH | 8 | 0.3% | Mar 31, 2026 | OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays e... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now