2026 CVE Vulnerabilities
53,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28447 | MEDIUM | 6.5 | 0.4% | Mar 5, 2026 | OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.1 contain a path traversal vulnerability in plugin installation that ... |
| CVE-2026-28394 | MEDIUM | 6.9 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.15 contain a denial of service vulnerability in the web_fetch tool that allows attacke... |
| CVE-2026-28492 | MEDIUM | 6.5 | 0.3% | Mar 5, 2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2026-28413 | MEDIUM | 6.1 | 0.2% | Mar 5, 2026 | Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a ... |
| CVE-2026-28405 | MEDIUM | 5.4 | 0.2% | Mar 5, 2026 | MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.1, the courses/<... |
| CVE-2026-22723 | MEDIUM | 6.5 | 0.2% | Mar 5, 2026 | Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry... |
| CVE-2026-28350 | MEDIUM | 6.1 | 0.3% | Mar 5, 2026 | lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, th... |
| CVE-2026-28348 | MEDIUM | 6.1 | 0.2% | Mar 5, 2026 | lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, th... |
| CVE-2026-28343 | MEDIUM | 6.1 | 0.3% | Mar 5, 2026 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. Starting in version 29.0.0 and prior to ver... |
| CVE-2026-28223 | MEDIUM | 6.1 | 0.5% | Mar 5, 2026 | Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a... |
| CVE-2026-28222 | MEDIUM | 6.1 | 0.4% | Mar 5, 2026 | Wagtail is an open source content management system built on Django. Prior to versions 6.3.8, 7.0.6, 7.2.3, and 7.3.1, a... |
| CVE-2026-21621 | MEDIUM | 5.3 | 0.3% | Mar 5, 2026 | Incorrect Authorization vulnerability in hexpm hexpm/hexpm ('Elixir.HexpmWeb.API.OAuthController' module) allows Privile... |
| CVE-2026-27723 | MEDIUM | 5.3 | 0.2% | Mar 5, 2026 | OpenProject is an open-source, web-based project management software. Prior to versions 17.0.5 and 17.1.2, an attacker c... |
| CVE-2026-27023 | MEDIUM | 5 | 0.2% | Mar 5, 2026 | Twenty is an open source CRM. Prior to version 1.18, the SSRF protection in SecureHttpClientService validated request UR... |
| CVE-2026-26998 | MEDIUM | 4.4 | 0.5% | Mar 5, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerabil... |
| CVE-2026-26276 | MEDIUM | 5.4 | 0.2% | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, an attacker can store an HTML/JavaScript payloa... |
| CVE-2026-26196 | MEDIUM | 5.3 | 0.3% | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params lik... |
| CVE-2026-26195 | MEDIUM | 6.1 | 0.2% | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, stored xss is still possible through unsafe tem... |
| CVE-2026-26022 | MEDIUM | 5.4 | 0.3% | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerabili... |
| CVE-2026-30785 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Ins... |
| CVE-2026-26377 | MEDIUM | 5.4 | 0.4% | Mar 5, 2026 | Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via the N... |
| CVE-2026-3236 | MEDIUM | 4.3 | 0.2% | Mar 5, 2026 | In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting i... |
| CVE-2026-28551 | MEDIUM | 4.7 | 0.1% | Mar 5, 2026 | Race condition vulnerability in the device security management module. Impact: Successful exploitation of this vulnerabi... |
| CVE-2026-28549 | MEDIUM | 4.7 | 0.1% | Mar 5, 2026 | Race condition vulnerability in the permission management service. Impact: Successful exploitation of this vulnerability... |
| CVE-2026-28548 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Vulnerability of improper verification in the email application. Impact: Successful exploitation of this vulnerability m... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now