2026 CVE Vulnerabilities
70,008 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28714 | MEDIUM | 4.8 | 0.2% | Mar 6, 2026 | Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect... |
| CVE-2026-28713 | HIGH | 7.1 | 0.2% | Mar 6, 2026 | Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyb... |
| CVE-2026-28712 | MEDIUM | 6.3 | 0.1% | Mar 6, 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec... |
| CVE-2026-28711 | MEDIUM | 6.3 | 0.1% | Mar 6, 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec... |
| CVE-2026-28710 | CRITICAL | 9.8 | 0.4% | Mar 6, 2026 | Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: A... |
| CVE-2026-28709 | MEDIUM | 4.3 | 0.2% | Mar 6, 2026 | Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cy... |
| CVE-2026-27778 | HIGH | 8.7 | 0.6% | Mar 6, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc... |
| CVE-2026-27770 | MEDIUM | 6.9 | 0.3% | Mar 6, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-24912 | HIGH | 8.6 | 0.4% | Mar 6, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ... |
| CVE-2026-22552 | CRITICAL | 9.8 | 0.9% | Mar 6, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat... |
| CVE-2026-26125 | CRITICAL | 9.8 | 1.2% | Mar 5, 2026 | Payment Orchestrator Service Elevation of Privilege Vulnerability |
| CVE-2026-26124 | MEDIUM | 6.7 | 0.5% | Mar 5, 2026 | '.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. |
| CVE-2026-26122 | MEDIUM | 6.5 | 1.0% | Mar 5, 2026 | Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose... |
| CVE-2026-23651 | MEDIUM | 6.7 | 0.6% | Mar 5, 2026 | Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. |
| CVE-2026-21536 | CRITICAL | 9.8 | 1.6% | Mar 5, 2026 | Microsoft Devices Pricing Program Remote Code Execution Vulnerability |
| CVE-2026-3606 | MEDIUM | 5.5 | 0.2% | Mar 5, 2026 | A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segme... |
| CVE-2026-2593 | MEDIUM | 6.4 | 0.2% | Mar 5, 2026 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2026-29613 | HIGH | 8.2 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in whi... |
| CVE-2026-29612 | HIGH | 7.5 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget... |
| CVE-2026-29611 | HIGH | 8.2 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be inst... |
| CVE-2026-29610 | HIGH | 8.8 | 0.5% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintend... |
| CVE-2026-29609 | HIGH | 8.7 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the fetchWithGuard function that alloc... |
| CVE-2026-29606 | MEDIUM | 6.5 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that al... |
| CVE-2026-28486 | MEDIUM | 5.5 | 0.2% | Mar 5, 2026 | OpenClaw versions 2026.1.16-2 prior to 2026.2.14 contain a path traversal vulnerability in archive extraction during ins... |
| CVE-2026-28485 | HIGH | 7.8 | 0.2% | Mar 5, 2026 | OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now