2026 CVE Vulnerabilities

68,737 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31938MEDIUM6.1jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the...
CVE-2026-31898MEDIUM6.5jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnot...
CVE-2026-31891MEDIUM6.5Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API acc...
CVE-2026-31865MEDIUM5.3Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun...
CVE-2026-30922HIGH7.5pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service ...
CVE-2026-30884CRITICAL9.6mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customi...
CVE-2026-2575MEDIUM5.3A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS...
CVE-2026-29112HIGH7.5DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dic...
CVE-2026-1926MEDIUM5.3The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2026-1780MEDIUM6.1The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all v...
CVE-2026-4356LOW2.4A flaw has been found in itsourcecode University Management System 1.0. Affected is an unknown function of the file /add...
CVE-2026-4268MEDIUM6.4The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgm...
CVE-2026-2603HIGH8.1A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an ...
CVE-2026-2092HIGH7.7A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly val...
CVE-2026-29056HIGH8.8Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registrat...
CVE-2026-28500CRITICAL9.1Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and inc...
CVE-2026-28499MEDIUM6.1LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correct...
CVE-2026-27545MEDIUM4.7OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attack...
CVE-2026-27524MEDIUM4.3OpenClaw versions prior to 2026.2.21 accept prototype-reserved keys in runtime /debug set override object values, allowi...
CVE-2026-27523HIGH7.5OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowe...
CVE-2026-27522MEDIUM5.5OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon ...
CVE-2026-22217MEDIUM6.1OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allow...
CVE-2026-22181HIGH7.6OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allows att...
CVE-2026-22180MEDIUM5.3OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling that allo...
CVE-2026-22179HIGH7.5OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now