2026 CVE Vulnerabilities
53,451 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33288 | HIGH | 8.8 | 0.4% | Mar 20, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi... |
| CVE-2026-32763 | HIGH | 8.2 | 0.4% | Mar 20, 2026 | Kysely is a type-safe TypeScript SQL query builder. Versions up to and including 0.28.11 has a SQL injection vulnerabili... |
| CVE-2026-32759 | HIGH | 8.1 | 1.9% | Mar 20, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-32756 | HIGH | 8.8 | 1.0% | Mar 20, 2026 | Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload... |
| CVE-2026-29189 | HIGH | 8.1 | 0.3% | Mar 20, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi... |
| CVE-2026-29109 | HIGH | 7.2 | 0.5% | Mar 20, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to... |
| CVE-2026-22733 | HIGH | 8.1 | 0.4% | Mar 20, 2026 | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application... |
| CVE-2026-30874 | HIGH | 7.8 | 0.3% | Mar 19, 2026 | OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in... |
| CVE-2026-29103 | HIGH | 7.2 | 0.5% | Mar 19, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Rem... |
| CVE-2026-29102 | HIGH | 8.8 | 0.5% | Mar 19, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi... |
| CVE-2026-29101 | HIGH | 7.5 | 0.5% | Mar 19, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi... |
| CVE-2026-29099 | HIGH | 8.8 | 0.3% | Mar 19, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi... |
| CVE-2026-29097 | HIGH | 7.5 | 0.3% | Mar 19, 2026 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions prior... |
| CVE-2026-22731 | HIGH | 8.1 | 0.3% | Mar 19, 2026 | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application... |
| CVE-2026-4342 | HIGH | 8.8 | 1.5% | Mar 19, 2026 | A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject config... |
| CVE-2026-32815 | HIGH | 7.5 | 0.4% | Mar 19, 2026 | SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the WebSocket endpoint (/ws) allows unaut... |
| CVE-2026-32752 | HIGH | 8.1 | 0.3% | Mar 19, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, the Th... |
| CVE-2026-32041 | HIGH | 7.8 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing bro... |
| CVE-2026-32036 | HIGH | 8.2 | 0.4% | Mar 19, 2026 | OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers ... |
| CVE-2026-32035 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in age... |
| CVE-2026-32034 | HIGH | 8.1 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowInsecure... |
| CVE-2026-32032 | HIGH | 7.8 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an arbitrary shell execution vulnerability in shell environment fallback th... |
| CVE-2026-32030 | HIGH | 8.2 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that accep... |
| CVE-2026-32027 | HIGH | 7.1 | 0.2% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are... |
| CVE-2026-32026 | HIGH | 8.6 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.24 contain an improper path validation vulnerability in sandbox media handling that al... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now