2026 CVE Vulnerabilities

53,128 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-35641HIGH7.8OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that ...
CVE-2026-35621HIGH7.1OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command fails to re-validat...
CVE-2026-35602HIGH7.1Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses th...
CVE-2026-35597HIGH7.5Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the TOTP failed-attempt lockout mechanis...
CVE-2026-35595HIGH8.3Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/projec...
CVE-2026-40224HIGH7.3In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach ...
CVE-2026-34481HIGH7.5Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions u...
CVE-2026-34480HIGH7.5Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to an...
CVE-2026-34479HIGH7.5The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standa...
CVE-2026-34478HIGH7.5Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions ...
CVE-2026-29002HIGH8.6CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin ...
CVE-2026-23782HIGH7.5An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated us...
CVE-2026-23780HIGH8.8An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug...
CVE-2026-6069HIGH7.5NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker...
CVE-2026-40217HIGH8.8LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/t...
CVE-2026-33092HIGH7.8Local privilege escalation due to improper handling of environment variables. The following products are affected: Acron...
CVE-2026-5777HIGH8.7This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service ov...
CVE-2026-39304HIGH7.5Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. A...
CVE-2026-4162HIGH7.1The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. Th...
CVE-2026-6038HIGH7.3A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. This impacts an unknown function...
CVE-2026-6037HIGH7.3A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This affects an unknown function...
CVE-2026-6036HIGH7.3A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. The impacted element is an unknown fu...
CVE-2026-33456HIGH7.6Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with a...
CVE-2026-6031HIGH7.3A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. This affects an unknown function of the ...
CVE-2026-5525HIGH7.8A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now