2026 CVE Vulnerabilities
68,165 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32265 | MEDIUM | 6.9 | 0.3% | Mar 18, 2026 | The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, una... |
| CVE-2026-32256 | HIGH | 7.5 | 0.4% | Mar 18, 2026 | music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF pars... |
| CVE-2026-32254 | HIGH | 7.1 | 0.3% | Mar 18, 2026 | Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not... |
| CVE-2026-31938 | MEDIUM | 6.1 | 0.3% | Mar 18, 2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the... |
| CVE-2026-31898 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnot... |
| CVE-2026-31891 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API acc... |
| CVE-2026-31865 | MEDIUM | 5.3 | 0.2% | Mar 18, 2026 | Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun... |
| CVE-2026-30922 | HIGH | 7.5 | 0.8% | Mar 18, 2026 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service ... |
| CVE-2026-30884 | CRITICAL | 9.6 | 0.2% | Mar 18, 2026 | mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customi... |
| CVE-2026-2575 | MEDIUM | 5.3 | 0.7% | Mar 18, 2026 | A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS... |
| CVE-2026-29112 | HIGH | 7.5 | 0.3% | Mar 18, 2026 | DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dic... |
| CVE-2026-1926 | MEDIUM | 5.3 | 0.3% | Mar 18, 2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2026-1780 | MEDIUM | 6.1 | 0.2% | Mar 18, 2026 | The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all v... |
| CVE-2026-4356 | LOW | 2.4 | 0.2% | Mar 18, 2026 | A flaw has been found in itsourcecode University Management System 1.0. Affected is an unknown function of the file /add... |
| CVE-2026-4268 | MEDIUM | 6.4 | 0.2% | Mar 18, 2026 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgm... |
| CVE-2026-2603 | HIGH | 8.1 | 0.4% | Mar 18, 2026 | A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an ... |
| CVE-2026-2092 | HIGH | 7.7 | 0.3% | Mar 18, 2026 | A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly val... |
| CVE-2026-29056 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registrat... |
| CVE-2026-28500 | CRITICAL | 9.1 | 0.3% | Mar 18, 2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and inc... |
| CVE-2026-28499 | MEDIUM | 6.1 | 0.3% | Mar 18, 2026 | LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correct... |
| CVE-2026-27545 | MEDIUM | 4.7 | 0.1% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attack... |
| CVE-2026-27524 | MEDIUM | 4.3 | 0.2% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.21 accept prototype-reserved keys in runtime /debug set override object values, allowi... |
| CVE-2026-27523 | HIGH | 7.5 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowe... |
| CVE-2026-27522 | MEDIUM | 5.5 | 0.4% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon ... |
| CVE-2026-22217 | MEDIUM | 6.1 | 0.1% | Mar 18, 2026 | OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allow... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now