2026 CVE Vulnerabilities

53,451 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-33288HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-32763HIGH8.2Kysely is a type-safe TypeScript SQL query builder. Versions up to and including 0.28.11 has a SQL injection vulnerabili...
CVE-2026-32759HIGH8.1File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-32756HIGH8.8Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload...
CVE-2026-29189HIGH8.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29109HIGH7.2SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to...
CVE-2026-22733HIGH8.1Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application...
CVE-2026-30874HIGH7.8OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in...
CVE-2026-29103HIGH7.2SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Rem...
CVE-2026-29102HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29101HIGH7.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29099HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29097HIGH7.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions prior...
CVE-2026-22731HIGH8.1Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application...
CVE-2026-4342HIGH8.8A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject config...
CVE-2026-32815HIGH7.5SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the WebSocket endpoint (/ws) allows unaut...
CVE-2026-32752HIGH8.1FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, the Th...
CVE-2026-32041HIGH7.8OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing bro...
CVE-2026-32036HIGH8.2OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers ...
CVE-2026-32035HIGH7.1OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in age...
CVE-2026-32034HIGH8.1OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowInsecure...
CVE-2026-32032HIGH7.8OpenClaw versions prior to 2026.2.22 contain an arbitrary shell execution vulnerability in shell environment fallback th...
CVE-2026-32030HIGH8.2OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that accep...
CVE-2026-32027HIGH7.1OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are...
CVE-2026-32026HIGH8.6OpenClaw versions prior to 2026.2.24 contain an improper path validation vulnerability in sandbox media handling that al...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now