2026 CVE Vulnerabilities

68,180 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-22168HIGH8.8OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows auth...
CVE-2026-29057MEDIUM6.5Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 1...
CVE-2026-28674HIGH7.2xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin...
CVE-2026-28673HIGH7.2xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin...
CVE-2026-27980HIGH7.5Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 1...
CVE-2026-27979HIGH7.5Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1...
CVE-2026-4355LOW3.5A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_...
CVE-2026-4354LOW3.5A vulnerability was identified in TRENDnet TEW-824DRU 1.010B01/1.04B01. The impacted element is the function sub_420A78 ...
CVE-2026-27978MEDIUM4.3Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1...
CVE-2026-27977MEDIUM5.4Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1...
CVE-2026-27895HIGH8.8LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d...
CVE-2026-27894HIGH8.8LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d...
CVE-2026-27811HIGH8.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a comma...
CVE-2026-27459CRITICAL9.8pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a u...
CVE-2026-27448MEDIUM5.3pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a u...
CVE-2026-26004MEDIUM6.5Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organi...
CVE-2026-26001HIGH8.8The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents...
CVE-2026-25937MEDIUM6.5GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malic...
CVE-2026-3856CRITICAL9.1IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an...
CVE-2026-22727HIGH7.5Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on a...
CVE-2026-21994CRITICAL9.8Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source P...
CVE-2026-20643MEDIUM5.4A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Backgrou...
CVE-2026-1264MEDIUM6.5IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ...
CVE-2026-4349MEDIUM6.3A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the...
CVE-2026-32842HIGH7.1Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows att...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now