2026 CVE Vulnerabilities
66,764 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32970 | LOW | 3.3 | 0.1% | Mar 31, 2026 | OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and ga... |
| CVE-2026-32921 | MEDIUM | 5 | 0.2% | Mar 31, 2026 | OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not b... |
| CVE-2026-32920 | HIGH | 8.8 | 0.3% | Mar 31, 2026 | OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust ve... |
| CVE-2026-32917 | CRITICAL | 9.8 | 2.0% | Mar 31, 2026 | OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that... |
| CVE-2026-32916 | CRITICAL | 9.8 | 0.5% | Mar 31, 2026 | OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes e... |
| CVE-2026-27854 | HIGH | 7.5 | 0.5% | Mar 31, 2026 | An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:... |
| CVE-2026-27853 | HIGH | 7.5 | 0.5% | Mar 31, 2026 | An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQ... |
| CVE-2026-24030 | HIGH | 7.5 | 0.5% | Mar 31, 2026 | An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HT... |
| CVE-2026-24029 | MEDIUM | 6.5 | 0.1% | Mar 31, 2026 | When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using... |
| CVE-2026-24028 | HIGH | 8.2 | 1.0% | Mar 31, 2026 | An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua cod... |
| CVE-2026-0397 | MEDIUM | 4.3 | 0.2% | Mar 31, 2026 | When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged... |
| CVE-2026-0396 | MEDIUM | 4.3 | 0.1% | Mar 31, 2026 | An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNS... |
| CVE-2026-4400 | MEDIUM | 6.5 | 0.2% | Mar 31, 2026 | Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot Millie chat that allows private conversations of ot... |
| CVE-2026-4399 | HIGH | 7.5 | 0.3% | Mar 31, 2026 | Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions ... |
| CVE-2026-34887 | MEDIUM | 6.5 | 0.1% | Mar 31, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubi... |
| CVE-2026-5197 | MEDIUM | 6.3 | 0.2% | Mar 31, 2026 | A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of... |
| CVE-2026-4317 | CRITICAL | 9.3 | 0.3% | Mar 31, 2026 | SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which co... |
| CVE-2026-5201 | HIGH | 7.5 | 1.1% | Mar 31, 2026 | A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loade... |
| CVE-2026-5196 | MEDIUM | 6.3 | 0.2% | Mar 31, 2026 | A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the fi... |
| CVE-2026-5195 | HIGH | 7.3 | 0.3% | Mar 31, 2026 | A flaw has been found in code-projects Student Membership System 1.0. This issue affects some unknown processing of the ... |
| CVE-2026-3107 | MEDIUM | 5.4 | 0.1% | Mar 31, 2026 | Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password impo... |
| CVE-2026-3106 | MEDIUM | 5.4 | 0.2% | Mar 31, 2026 | Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionalit... |
| CVE-2026-5186 | MEDIUM | 5.3 | 0.1% | Mar 31, 2026 | A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb... |
| CVE-2026-5185 | MEDIUM | 5.3 | 0.2% | Mar 31, 2026 | A security flaw has been discovered in Nothings stb_image up to 2.30. This affects the function stbi__gif_load_next of t... |
| CVE-2026-5184 | HIGH | 8.8 | 5.8% | Mar 31, 2026 | A vulnerability was identified in TRENDnet TEW-713RE up to 1.02. The impacted element is an unknown function of the file... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now