2026 CVE Vulnerabilities

67,237 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32277HIGH8.7Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cro...
CVE-2026-32276HIGH8.8Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the...
CVE-2026-32066——Rejected reason: This CVE ID has been rejected.
CVE-2026-32047——Rejected reason: This CVE ID has been rejected.
CVE-2026-32012——Rejected reason: This CVE ID has been rejected.
CVE-2026-29111MEDIUM5.5systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call...
CVE-2026-28483——Rejected reason: This CVE ID has been rejected.
CVE-2026-28455——Rejected reason: This CVE ID has been rejected.
CVE-2026-27646MEDIUM6.1OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authori...
CVE-2026-27183MEDIUM5.3OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wrapper ...
CVE-2026-22173——Rejected reason: This CVE ID has been rejected.
CVE-2026-1940HIGH7.5An incomplete fix for CVE-2024-47778 allows an out-of-bounds read in gst_wavparse_adtl_chunk() function. The patch added...
CVE-2026-4597MEDIUM6.3A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. Impacted is the function selectAll of the ...
CVE-2026-4368HIGH7.7Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN,...
CVE-2026-3055CRITICAL9.8Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory ove...
CVE-2026-23882HIGH7.2Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creati...
CVE-2026-23488MEDIUM5.3Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the /api/v1/comment/create endpoint has an una...
CVE-2026-23487MEDIUM6.5Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.deta...
CVE-2026-23486MEDIUM5.3Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all use...
CVE-2026-23485MEDIUM5.3Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal ...
CVE-2026-23484MEDIUM6.5Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filter...
CVE-2026-23483MEDIUM5.3Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses...
CVE-2026-23482HIGH7.5Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the file server endpoint does not perform perm...
CVE-2026-23481MEDIUM6.5Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an authenticated arbitrary file write...
CVE-2026-23480HIGH8.8Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is a privilege escalation vulnerability....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now