2026 CVE Vulnerabilities

51,952 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-41485HIGH7.7Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an...
CVE-2026-41324HIGH7.5basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded me...
CVE-2026-41068HIGH7.7Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cros...
CVE-2026-41317HIGH7.5Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-...
CVE-2026-41316HIGH8.1ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` ...
CVE-2026-41309HIGH8.2Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are ...
CVE-2026-33318HIGH8.8Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) ...
CVE-2026-33317HIGH8.7OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-33208HIGH8.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /co...
CVE-2026-33077HIGH7.5Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the old...
CVE-2026-32952HIGH7.5go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NT...
CVE-2026-41325HIGH8.8Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perfor...
CVE-2026-34587HIGH8.1Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control w...
CVE-2026-32870HIGH7.5Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>...
CVE-2026-40623HIGH8.1A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameter...
CVE-2026-35064HIGH8.7A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the...
CVE-2026-31952HIGH8.1Xibo is an open source digital signage platform with a web content management system and Windows display player software...
CVE-2026-27841HIGH8.4A vulnerability in SenseLive X3050's web management interface allows state-changing operations to be triggered without p...
CVE-2026-6732HIGH7.5A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definit...
CVE-2026-41361HIGH7.1OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 special-use ranges. ...
CVE-2026-41359HIGH8.8OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write perm...
CVE-2026-41355HIGH7.3OpenClaw before 2026.3.28 contains an arbitrary code execution vulnerability in mirror mode that converts untrusted sand...
CVE-2026-41353HIGH8.1OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attac...
CVE-2026-41352HIGH8.8OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node ...
CVE-2026-41349HIGH8.8OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now