2026 CVE Vulnerabilities

53,238 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-34573HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34240HIGH7.5JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose cou...
CVE-2026-34227HIGH8.8Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click ...
CVE-2026-30284HIGH8.6An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical int...
CVE-2026-22561HIGH7.8Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.336...
CVE-2026-34504HIGH8.3OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-prov...
CVE-2026-34503HIGH8.6OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. ...
CVE-2026-34377HIGH8.1ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic...
CVE-2026-34373HIGH8.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34210HIGH8.1mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method ...
CVE-2026-34209HIGH7.5mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the tempo/session cooperative clo...
CVE-2026-34202HIGH7.5ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerabi...
CVE-2026-34200HIGH7.5Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nhost CLI MCP server, when expli...
CVE-2026-34172HIGH8.8Giskard is an open-source Python library for testing and evaluating agentic systems. Prior to versions 0.3.4 and 1.0.2b1...
CVE-2026-34163HIGH7.7FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoi...
CVE-2026-33581HIGH8.6OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbi...
CVE-2026-33577HIGH8.6OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that...
CVE-2026-30309HIGH7.8InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist ...
CVE-2026-29870HIGH7.6A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file wri...
CVE-2026-0596HIGH7.8A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_u...
CVE-2026-3308HIGH7.8An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously c...
CVE-2026-5198HIGH7.3A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown functi...
CVE-2026-4267HIGH7.2The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site S...
CVE-2026-32988HIGH7.5OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary fi...
CVE-2026-32982HIGH8.7OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now