2026 CVE Vulnerabilities
53,531 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22729 | HIGH | 8.6 | 0.5% | Mar 18, 2026 | A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass... |
| CVE-2026-22323 | HIGH | 7.1 | 0.2% | Mar 18, 2026 | A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick ... |
| CVE-2026-22322 | HIGH | 7.1 | 0.3% | Mar 18, 2026 | A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthentica... |
| CVE-2026-22317 | HIGH | 7.2 | 1.0% | Mar 18, 2026 | A command injection vulnerability in the device’s Root CA certificate transfer workflow allows a high-privileged attacke... |
| CVE-2026-32608 | HIGH | 7 | 0.2% | Mar 18, 2026 | Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to conf... |
| CVE-2026-32606 | HIGH | 7.6 | 0.1% | Mar 18, 2026 | IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd... |
| CVE-2026-32596 | HIGH | 7.5 | 1.6% | Mar 18, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authent... |
| CVE-2026-32268 | HIGH | 8.7 | 0.3% | Mar 18, 2026 | The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the... |
| CVE-2026-32256 | HIGH | 7.5 | 0.4% | Mar 18, 2026 | music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF pars... |
| CVE-2026-32254 | HIGH | 7.1 | 0.3% | Mar 18, 2026 | Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not... |
| CVE-2026-30922 | HIGH | 7.5 | 0.8% | Mar 18, 2026 | pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service ... |
| CVE-2026-29112 | HIGH | 7.5 | 0.3% | Mar 18, 2026 | DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dic... |
| CVE-2026-2603 | HIGH | 8.1 | 0.4% | Mar 18, 2026 | A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an ... |
| CVE-2026-2092 | HIGH | 7.7 | 0.3% | Mar 18, 2026 | A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly val... |
| CVE-2026-29056 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registrat... |
| CVE-2026-27523 | HIGH | 7.5 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowe... |
| CVE-2026-22181 | HIGH | 7.6 | 0.2% | Mar 18, 2026 | OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allows att... |
| CVE-2026-22179 | HIGH | 7.5 | 0.6% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows... |
| CVE-2026-22178 | HIGH | 8.2 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the str... |
| CVE-2026-22177 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars... |
| CVE-2026-22175 | HIGH | 7.1 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always ... |
| CVE-2026-22169 | HIGH | 7.1 | 0.2% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows... |
| CVE-2026-22168 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows auth... |
| CVE-2026-28674 | HIGH | 7.2 | 0.3% | Mar 18, 2026 | xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin... |
| CVE-2026-28673 | HIGH | 7.2 | 0.6% | Mar 18, 2026 | xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now