2026 CVE Vulnerabilities
50,985 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34595 | MEDIUM | 4.3 | 0.3% | Mar 31, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-34574 | MEDIUM | 5.4 | 0.2% | Mar 31, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-34237 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 0.83.0, 1.0.1, a... |
| CVE-2026-34231 | MEDIUM | 6.1 | 0.2% | Mar 31, 2026 | Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exis... |
| CVE-2026-34219 | MEDIUM | 5.9 | 0.4% | Mar 31, 2026 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Ru... |
| CVE-2026-34218 | MEDIUM | 6.3 | 0.2% | Mar 31, 2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.... |
| CVE-2026-22569 | MEDIUM | 5.3 | 0.2% | Mar 31, 2026 | An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amoun... |
| CVE-2026-4799 | MEDIUM | 4.3 | 0.2% | Mar 31, 2026 | In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an unt... |
| CVE-2026-34363 | MEDIUM | 5.3 | 0.4% | Mar 31, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-34224 | MEDIUM | 4.4 | 0.3% | Mar 31, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-34214 | MEDIUM | 6.5 | 0.2% | Mar 31, 2026 | Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connecto... |
| CVE-2026-34165 | MEDIUM | 5 | 0.1% | Mar 31, 2026 | go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vu... |
| CVE-2026-33580 | MEDIUM | 6.5 | 0.4% | Mar 31, 2026 | OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication th... |
| CVE-2026-33578 | MEDIUM | 4.3 | 0.3% | Mar 31, 2026 | OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where... |
| CVE-2026-33576 | MEDIUM | 6.9 | 0.4% | Mar 31, 2026 | OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. ... |
| CVE-2026-33276 | MEDIUM | 5.4 | 0.1% | Mar 31, 2026 | Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to c... |
| CVE-2026-20915 | MEDIUM | 5.4 | 0.1% | Mar 31, 2026 | Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permiss... |
| CVE-2026-34155 | MEDIUM | 5.3 | 0.1% | Mar 31, 2026 | RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' form... |
| CVE-2026-3191 | MEDIUM | 5.4 | 0.2% | Mar 31, 2026 | The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2... |
| CVE-2026-3139 | MEDIUM | 4.3 | 0.2% | Mar 31, 2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2026-34506 | MEDIUM | 4.3 | 0.3% | Mar 31, 2026 | OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unau... |
| CVE-2026-34505 | MEDIUM | 6.9 | 0.3% | Mar 31, 2026 | OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypa... |
| CVE-2026-32977 | MEDIUM | 6.3 | 0.1% | Mar 31, 2026 | OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that u... |
| CVE-2026-32921 | MEDIUM | 5 | 0.2% | Mar 31, 2026 | OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not b... |
| CVE-2026-24029 | MEDIUM | 6.5 | 0.1% | Mar 31, 2026 | When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now