2026 CVE Vulnerabilities
67,338 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-29097 | HIGH | 7.5 | 0.3% | Mar 19, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions prior... |
| CVE-2026-29096 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi... |
| CVE-2026-22732 | CRITICAL | 9.1 | 0.5% | Mar 19, 2026 | When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility... |
| CVE-2026-22731 | HIGH | 8.1 | 0.3% | Mar 19, 2026 | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application... |
| CVE-2026-4342 | HIGH | 8.8 | 1.5% | Mar 19, 2026 | A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject config... |
| CVE-2026-4159 | LOW | 3.3 | 0.1% | Mar 19, 2026 | 1-byte OOB heap read in wc_PKCS7_DecodeEnvelopedData via zero-length encrypted content. A vulnerability existed in wolfS... |
| CVE-2026-33410 | MEDIUM | 5.4 | 0.2% | Mar 19, 2026 | Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have two au... |
| CVE-2026-33394 | LOW | 2.7 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the Post E... |
| CVE-2026-33393 | MEDIUM | 4.3 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `allow... |
| CVE-2026-33355 | MEDIUM | 6.5 | 0.4% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `/priv... |
| CVE-2026-32815 | HIGH | 7.5 | 0.4% | Mar 19, 2026 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the WebSocket endpoint (/ws) allows unaut... |
| CVE-2026-32754 | CRITICAL | 9.3 | 0.5% | Mar 19, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulner... |
| CVE-2026-32753 | MEDIUM | 5.4 | 0.2% | Mar 19, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, bypass... |
| CVE-2026-32752 | HIGH | 8.1 | 0.3% | Mar 19, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, the Th... |
| CVE-2026-32751 | CRITICAL | 9 | 0.8% | Mar 19, 2026 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the mobile file tree (MobileFiles.ts) ren... |
| CVE-2026-32750 | MEDIUM | 6.8 | 0.4% | Mar 19, 2026 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the l... |
| CVE-2026-32194 | CRITICAL | 9.8 | 0.7% | Mar 19, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an u... |
| CVE-2026-32099 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, when a use... |
| CVE-2026-32041 | HIGH | 7.8 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing bro... |
| CVE-2026-32040 | MEDIUM | 6.1 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows at... |
| CVE-2026-32039 | MEDIUM | 6.5 | 0.2% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy mat... |
| CVE-2026-32038 | CRITICAL | 9 | 0.3% | Mar 19, 2026 | OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to joi... |
| CVE-2026-32037 | MEDIUM | 6.5 | 0.2% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts al... |
| CVE-2026-32036 | HIGH | 8.2 | 0.4% | Mar 19, 2026 | OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers ... |
| CVE-2026-32035 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in age... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now