2026 CVE Vulnerabilities

68,165 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32265MEDIUM6.9The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, una...
CVE-2026-32256HIGH7.5music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF pars...
CVE-2026-32254HIGH7.1Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not...
CVE-2026-31938MEDIUM6.1jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the...
CVE-2026-31898MEDIUM6.5jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnot...
CVE-2026-31891MEDIUM6.5Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API acc...
CVE-2026-31865MEDIUM5.3Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun...
CVE-2026-30922HIGH7.5pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service ...
CVE-2026-30884CRITICAL9.6mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customi...
CVE-2026-2575MEDIUM5.3A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS...
CVE-2026-29112HIGH7.5DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dic...
CVE-2026-1926MEDIUM5.3The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2026-1780MEDIUM6.1The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all v...
CVE-2026-4356LOW2.4A flaw has been found in itsourcecode University Management System 1.0. Affected is an unknown function of the file /add...
CVE-2026-4268MEDIUM6.4The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgm...
CVE-2026-2603HIGH8.1A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an ...
CVE-2026-2092HIGH7.7A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly val...
CVE-2026-29056HIGH8.8Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registrat...
CVE-2026-28500CRITICAL9.1Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and inc...
CVE-2026-28499MEDIUM6.1LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correct...
CVE-2026-27545MEDIUM4.7OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attack...
CVE-2026-27524MEDIUM4.3OpenClaw versions prior to 2026.2.21 accept prototype-reserved keys in runtime /debug set override object values, allowi...
CVE-2026-27523HIGH7.5OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowe...
CVE-2026-27522MEDIUM5.5OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon ...
CVE-2026-22217MEDIUM6.1OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allow...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now