2026 CVE Vulnerabilities

53,327 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-32725HIGH8.3SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp...
CVE-2026-30279HIGH8.4An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overw...
CVE-2026-30277HIGH8.4An arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to ove...
CVE-2026-2123HIGH7.8A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under speci...
CVE-2026-24165HIGH8.8NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful explo...
CVE-2026-5204HIGH8.8A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/we...
CVE-2026-5087HIGH7.5PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random bytes insecurely. PAGI::Mi...
CVE-2026-4818HIGH8.1In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary priv...
CVE-2026-34573HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34240HIGH7.5JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose cou...
CVE-2026-34227HIGH8.8Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click ...
CVE-2026-30284HIGH8.6An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical int...
CVE-2026-22561HIGH7.8Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.336...
CVE-2026-34504HIGH8.3OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-prov...
CVE-2026-34503HIGH8.6OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. ...
CVE-2026-34377HIGH8.1ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic...
CVE-2026-34373HIGH8.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34210HIGH8.1mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method ...
CVE-2026-34209HIGH7.5mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the tempo/session cooperative clo...
CVE-2026-34202HIGH7.5ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerabi...
CVE-2026-34200HIGH7.5Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nhost CLI MCP server, when expli...
CVE-2026-34172HIGH8.8Giskard is an open-source Python library for testing and evaluating agentic systems. Prior to versions 0.3.4 and 1.0.2b1...
CVE-2026-34163HIGH7.7FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoi...
CVE-2026-33581HIGH8.6OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbi...
CVE-2026-33577HIGH8.6OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now