2026 CVE Vulnerabilities

50,985 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-34595MEDIUM4.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34574MEDIUM5.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34237MEDIUM6.1MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 0.83.0, 1.0.1, a...
CVE-2026-34231MEDIUM6.1Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exis...
CVE-2026-34219MEDIUM5.9libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Ru...
CVE-2026-34218MEDIUM6.3ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4....
CVE-2026-22569MEDIUM5.3An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amoun...
CVE-2026-4799MEDIUM4.3In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an unt...
CVE-2026-34363MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34224MEDIUM4.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34214MEDIUM6.5Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connecto...
CVE-2026-34165MEDIUM5go-git is an extensible git implementation library written in pure Go. From version 5.0.0 to before version 5.17.1, a vu...
CVE-2026-33580MEDIUM6.5OpenClaw before 2026.3.28 contains a missing rate limiting vulnerability in the Nextcloud Talk webhook authentication th...
CVE-2026-33578MEDIUM4.3OpenClaw before 2026.3.28 contains a sender policy bypass vulnerability in the Google Chat and Zalouser extensions where...
CVE-2026-33576MEDIUM6.9OpenClaw before 2026.3.28 downloads and stores inbound media from Zalo channels before validating sender authorization. ...
CVE-2026-33276MEDIUM5.4Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to c...
CVE-2026-20915MEDIUM5.4Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permiss...
CVE-2026-34155MEDIUM5.3RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' form...
CVE-2026-3191MEDIUM5.4The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2...
CVE-2026-3139MEDIUM4.3The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2026-34506MEDIUM4.3OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unau...
CVE-2026-34505MEDIUM6.9OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypa...
CVE-2026-32977MEDIUM6.3OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that u...
CVE-2026-32921MEDIUM5OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not b...
CVE-2026-24029MEDIUM6.5When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now