2026 CVE Vulnerabilities
51,297 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27397 | MEDIUM | 6.5 | 0.2% | Mar 19, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro ... |
| CVE-2026-1276 | MEDIUM | 5.4 | 0.1% | Mar 19, 2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows a... |
| CVE-2026-31997 | MEDIUM | 6.7 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.1 fail to pin executable identity for non-path-like argv[0] tokens in system.run appro... |
| CVE-2026-31996 | MEDIUM | 4.4 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.19 tools.exec.safeBins contains an input validation bypass vulnerability that allows a... |
| CVE-2026-31993 | MEDIUM | 6.4 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion app that... |
| CVE-2026-31991 | MEDIUM | 4.6 | 0.2% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where Signal group allowlist policy i... |
| CVE-2026-31989 | MEDIUM | 6.3 | 0.2% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation redirect ... |
| CVE-2026-29608 | MEDIUM | 6.7 | 0.1% | Mar 19, 2026 | OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewriting ch... |
| CVE-2026-28449 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed ... |
| CVE-2026-27670 | MEDIUM | 5.8 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.2 contain a race condition vulnerability in ZIP extraction that allows local attackers... |
| CVE-2026-32743 | MEDIUM | 6.5 | 0.4% | Mar 19, 2026 | PX4 is an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable to ... |
| CVE-2026-32736 | MEDIUM | 4.3 | 0.2% | Mar 18, 2026 | The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. An Insecure Direct Object... |
| CVE-2026-33163 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-33042 | MEDIUM | 5.3 | 0.3% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32742 | MEDIUM | 4.3 | 0.3% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32723 | MEDIUM | 4.7 | 0.1% | Mar 18, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.35, SandboxJS timers have an execution-quota bypass. A global... |
| CVE-2026-32722 | MEDIUM | 6.1 | 0.3% | Mar 18, 2026 | Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process ... |
| CVE-2026-32703 | MEDIUM | 5.4 | 0.2% | Mar 18, 2026 | OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 1... |
| CVE-2026-32700 | MEDIUM | 5.3 | 0.3% | Mar 18, 2026 | Devise is an authentication solution for Rails based on Warden. Prior to version 5.0.3, a race condition in Devise's Con... |
| CVE-2026-25745 | MEDIUM | 6.5 | 0.3% | Mar 18, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. In versions up ... |
| CVE-2026-32632 | MEDIUM | 5.9 | 0.2% | Mar 18, 2026 | Glances is an open-source system cross-platform monitoring tool. Glances recently added DNS rebinding protection for the... |
| CVE-2026-30048 | MEDIUM | 5.4 | 0.2% | Mar 18, 2026 | A stored cross-site scripting (XSS) vulnerability exists in the NotChatbot WebChat widget thru 1.4.4. User-supplied inpu... |
| CVE-2026-26948 | MEDIUM | 4.9 | 0.3% | Mar 18, 2026 | Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to 7.10.9... |
| CVE-2026-26945 | MEDIUM | 5.3 | 0.2% | Mar 18, 2026 | Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.1... |
| CVE-2026-23267 | MEDIUM | 5.5 | 0.1% | Mar 18, 2026 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix IS_CHECKPOINTED flag inconsistency issue ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now