2026 CVE Vulnerabilities
53,345 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32978 | HIGH | 7.5 | 0.2% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable f... |
| CVE-2026-32972 | HIGH | 7.1 | 0.3% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only oper... |
| CVE-2026-32914 | HIGH | 8.8 | 0.3% | Mar 29, 2026 | OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handle... |
| CVE-2026-5043 | HIGH | 8.8 | 0.8% | Mar 29, 2026 | A weakness has been identified in Belkin F9K1122 1.00.33. The impacted element is the function formSetPassword of the fi... |
| CVE-2026-5042 | HIGH | 8.8 | 0.7% | Mar 29, 2026 | A security flaw has been discovered in Belkin F9K1122 1.00.33. The affected element is the function formCrossBandSwitch ... |
| CVE-2026-5036 | HIGH | 8.8 | 0.6% | Mar 29, 2026 | A vulnerability was found in Tenda 4G06 04.06.01.29. This vulnerability affects the function fromDhcpListClient of the f... |
| CVE-2026-5024 | HIGH | 8.8 | 0.8% | Mar 29, 2026 | A vulnerability was found in D-Link DIR-513 1.10. This issue affects the function formSetEmail of the file /goform/formS... |
| CVE-2026-5021 | HIGH | 8.8 | 0.6% | Mar 29, 2026 | A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromPPTPUserSetting of the file /goform/PPTPUserS... |
| CVE-2026-5016 | HIGH | 7.3 | 0.3% | Mar 28, 2026 | A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the ... |
| CVE-2026-5012 | HIGH | 7.3 | 1.4% | Mar 28, 2026 | A flaw has been found in elecV2 elecV2P up to 3.8.3. This issue affects the function pm2run of the file /rpc. Executing ... |
| CVE-2026-5004 | HIGH | 8.8 | 0.7% | Mar 28, 2026 | A vulnerability was determined in Wavlink WL-WN579X3-C 231124. This impacts the function sub_4019FC of the file /cgi-bin... |
| CVE-2026-5002 | HIGH | 7.3 | 0.3% | Mar 28, 2026 | A vulnerability has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The impacted el... |
| CVE-2026-5001 | HIGH | 7.3 | 0.3% | Mar 28, 2026 | A flaw has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The affected element is ... |
| CVE-2026-5000 | HIGH | 7.3 | 0.4% | Mar 28, 2026 | A vulnerability was detected in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. Impacted is the f... |
| CVE-2026-4998 | HIGH | 7.3 | 0.5% | Mar 28, 2026 | A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor... |
| CVE-2026-4996 | HIGH | 7.3 | 0.3% | Mar 28, 2026 | A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_questi... |
| CVE-2026-4987 | HIGH | 7.5 | 0.3% | Mar 28, 2026 | The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amo... |
| CVE-2026-1679 | HIGH | 7.8 | 0.2% | Mar 28, 2026 | The eswifi socket offload driver copies user-provided payloads into a fixed buffer without checking available space; ove... |
| CVE-2026-4248 | HIGH | 8 | 0.2% | Mar 27, 2026 | The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl... |
| CVE-2026-33991 | HIGH | 8.8 | 0.4% | Mar 27, 2026 | WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php... |
| CVE-2026-4990 | HIGH | 7.3 | 0.4% | Mar 27, 2026 | A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the ... |
| CVE-2026-34226 | HIGH | 7.5 | 0.5% | Mar 27, 2026 | Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Versions prior to 20.8.9... |
| CVE-2026-33980 | HIGH | 8.1 | 0.4% | Mar 27, 2026 | Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL querie... |
| CVE-2026-33979 | HIGH | 8.2 | 0.4% | Mar 27, 2026 | Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.hea... |
| CVE-2026-33955 | HIGH | 8.6 | 0.3% | Mar 27, 2026 | Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now