2026 CVE Vulnerabilities
51,340 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22320 | MEDIUM | 6.5 | 0.3% | Mar 18, 2026 | A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Tel... |
| CVE-2026-22319 | MEDIUM | 4.9 | 0.3% | Mar 18, 2026 | A stack-based buffer overflow in the device's file installation workflow allows a high-privileged attacker to send overs... |
| CVE-2026-22318 | MEDIUM | 4.9 | 0.3% | Mar 18, 2026 | A stack-based buffer overflow vulnerability in the device's file transfer parameter workflow allows a high-privileged at... |
| CVE-2026-22316 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | A remote attacker with user privileges for the webUI can use the setting of the TFTP Filename with a POST Request to tri... |
| CVE-2026-3512 | MEDIUM | 6.1 | 0.2% | Mar 18, 2026 | The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter... |
| CVE-2026-4366 | MEDIUM | 5.8 | 0.2% | Mar 18, 2026 | A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirect... |
| CVE-2026-33058 | MEDIUM | 6.5 | 0.3% | Mar 18, 2026 | Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQ... |
| CVE-2026-32265 | MEDIUM | 6.9 | 0.3% | Mar 18, 2026 | The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, una... |
| CVE-2026-31938 | MEDIUM | 6.1 | 0.3% | Mar 18, 2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the... |
| CVE-2026-31898 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnot... |
| CVE-2026-31891 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API acc... |
| CVE-2026-31865 | MEDIUM | 5.3 | 0.2% | Mar 18, 2026 | Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun... |
| CVE-2026-2575 | MEDIUM | 5.3 | 0.5% | Mar 18, 2026 | A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS... |
| CVE-2026-1926 | MEDIUM | 5.3 | 0.3% | Mar 18, 2026 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2026-1780 | MEDIUM | 6.1 | 0.2% | Mar 18, 2026 | The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all v... |
| CVE-2026-4268 | MEDIUM | 6.4 | 0.2% | Mar 18, 2026 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgm... |
| CVE-2026-28499 | MEDIUM | 6.1 | 0.3% | Mar 18, 2026 | LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correct... |
| CVE-2026-27545 | MEDIUM | 4.7 | 0.1% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attack... |
| CVE-2026-27524 | MEDIUM | 4.3 | 0.2% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.21 accept prototype-reserved keys in runtime /debug set override object values, allowi... |
| CVE-2026-27522 | MEDIUM | 5.5 | 0.4% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon ... |
| CVE-2026-22217 | MEDIUM | 6.1 | 0.1% | Mar 18, 2026 | OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allow... |
| CVE-2026-22180 | MEDIUM | 5.3 | 0.1% | Mar 18, 2026 | OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling that allo... |
| CVE-2026-22174 | MEDIUM | 6.8 | 0.1% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback ... |
| CVE-2026-22170 | MEDIUM | 6.5 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability... |
| CVE-2026-29057 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 1... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now