2026 CVE Vulnerabilities
66,804 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34155 | MEDIUM | 5.3 | 0.1% | Mar 31, 2026 | RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' form... |
| CVE-2026-30310 | CRITICAL | 9.8 | 0.5% | Mar 31, 2026 | In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all ... |
| CVE-2026-5198 | HIGH | 7.3 | 0.3% | Mar 31, 2026 | A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown functi... |
| CVE-2026-4267 | HIGH | 7.2 | 0.3% | Mar 31, 2026 | The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site S... |
| CVE-2026-3191 | MEDIUM | 5.4 | 0.2% | Mar 31, 2026 | The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2... |
| CVE-2026-3139 | MEDIUM | 4.3 | 0.2% | Mar 31, 2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2026-34509 | — | — | — | Mar 31, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-34508 | — | — | — | Mar 31, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-34506 | MEDIUM | 4.3 | 0.3% | Mar 31, 2026 | OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unau... |
| CVE-2026-34505 | MEDIUM | 6.9 | 0.3% | Mar 31, 2026 | OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypa... |
| CVE-2026-32988 | HIGH | 7.5 | 0.1% | Mar 31, 2026 | OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary fi... |
| CVE-2026-32982 | HIGH | 8.7 | 0.4% | Mar 31, 2026 | OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes... |
| CVE-2026-32977 | MEDIUM | 6.3 | 0.1% | Mar 31, 2026 | OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that u... |
| CVE-2026-32976 | HIGH | 7.1 | 0.2% | Mar 31, 2026 | OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected s... |
| CVE-2026-32971 | HIGH | 8 | 0.3% | Mar 31, 2026 | OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays e... |
| CVE-2026-32970 | LOW | 3.3 | 0.1% | Mar 31, 2026 | OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and ga... |
| CVE-2026-32921 | MEDIUM | 5 | 0.2% | Mar 31, 2026 | OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not b... |
| CVE-2026-32920 | HIGH | 8.8 | 0.3% | Mar 31, 2026 | OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust ve... |
| CVE-2026-32917 | CRITICAL | 9.8 | 2.0% | Mar 31, 2026 | OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that... |
| CVE-2026-32916 | CRITICAL | 9.8 | 0.5% | Mar 31, 2026 | OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes e... |
| CVE-2026-27854 | HIGH | 7.5 | 0.5% | Mar 31, 2026 | An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:... |
| CVE-2026-27853 | HIGH | 7.5 | 0.5% | Mar 31, 2026 | An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQ... |
| CVE-2026-24030 | HIGH | 7.5 | 0.5% | Mar 31, 2026 | An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HT... |
| CVE-2026-24029 | MEDIUM | 6.5 | 0.1% | Mar 31, 2026 | When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using... |
| CVE-2026-24028 | HIGH | 8.2 | 1.0% | Mar 31, 2026 | An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua cod... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now