2026 CVE Vulnerabilities

67,338 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29097HIGH7.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions prior...
CVE-2026-29096MEDIUM6.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-22732CRITICAL9.1When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility...
CVE-2026-22731HIGH8.1Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application...
CVE-2026-4342HIGH8.8A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject config...
CVE-2026-4159LOW3.31-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. A vulnerability existed in wolfS...
CVE-2026-33410MEDIUM5.4Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have two au...
CVE-2026-33394LOW2.7Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Post E...
CVE-2026-33393MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `allow...
CVE-2026-33355MEDIUM6.5Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `/priv...
CVE-2026-32815HIGH7.5SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the WebSocket endpoint (/ws) allows unaut...
CVE-2026-32754CRITICAL9.3FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulner...
CVE-2026-32753MEDIUM5.4FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, bypass...
CVE-2026-32752HIGH8.1FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, the Th...
CVE-2026-32751CRITICAL9SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) ren...
CVE-2026-32750MEDIUM6.8SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the l...
CVE-2026-32194CRITICAL9.8Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an u...
CVE-2026-32099MEDIUM6.5Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, when a use...
CVE-2026-32041HIGH7.8OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing bro...
CVE-2026-32040MEDIUM6.1OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows at...
CVE-2026-32039MEDIUM6.5OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy mat...
CVE-2026-32038CRITICAL9OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to joi...
CVE-2026-32037MEDIUM6.5OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts al...
CVE-2026-32036HIGH8.2OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers ...
CVE-2026-32035HIGH7.1OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in age...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now