2026 CVE Vulnerabilities

53,329 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-33577HIGH8.6OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that...
CVE-2026-30309HIGH7.8InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist ...
CVE-2026-29870HIGH7.6A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file wri...
CVE-2026-0596HIGH7.8A command injection vulnerability exists in mlflow/mlflow when serving a model with `enable_mlserver=True`. The `model_u...
CVE-2026-3308HIGH7.8An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously c...
CVE-2026-5198HIGH7.3A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown functi...
CVE-2026-4267HIGH7.2The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site S...
CVE-2026-32988HIGH7.5OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary fi...
CVE-2026-32982HIGH8.7OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes...
CVE-2026-32976HIGH7.1OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected s...
CVE-2026-32971HIGH8OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays e...
CVE-2026-32920HIGH8.8OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust ve...
CVE-2026-27854HIGH7.5An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:...
CVE-2026-27853HIGH7.5An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQ...
CVE-2026-24030HIGH7.5An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HT...
CVE-2026-24028HIGH8.2An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua cod...
CVE-2026-4399HIGH7.5Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions ...
CVE-2026-5201HIGH7.5A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loade...
CVE-2026-5195HIGH7.3A flaw has been found in code-projects Student Membership System 1.0. This issue affects some unknown processing of the ...
CVE-2026-5184HIGH8.8A vulnerability was identified in TRENDnet TEW-713RE up to 1.02. The impacted element is an unknown function of the file...
CVE-2026-5182HIGH7.3A vulnerability was found in SourceCodester Teacher Record System 1.0. Impacted is an unknown function of the file Teach...
CVE-2026-5180HIGH7.3A flaw has been found in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code o...
CVE-2026-5179HIGH7.3A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This affects an unknown part of th...
CVE-2026-5178HIGH8.8A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this issue is the func...
CVE-2026-5177HIGH8.8A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now