2026 CVE Vulnerabilities

53,531 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-22729HIGH8.6A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass...
CVE-2026-22323HIGH7.1A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick ...
CVE-2026-22322HIGH7.1A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthentica...
CVE-2026-22317HIGH7.2A command injection vulnerability in the device’s Root CA certificate transfer workflow allows a high-privileged attacke...
CVE-2026-32608HIGH7Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to conf...
CVE-2026-32606HIGH7.6IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd...
CVE-2026-32596HIGH7.5Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authent...
CVE-2026-32268HIGH8.7The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the...
CVE-2026-32256HIGH7.5music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF pars...
CVE-2026-32254HIGH7.1Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not...
CVE-2026-30922HIGH7.5pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service ...
CVE-2026-29112HIGH7.5DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dic...
CVE-2026-2603HIGH8.1A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an ...
CVE-2026-2092HIGH7.7A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly val...
CVE-2026-29056HIGH8.8Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registrat...
CVE-2026-27523HIGH7.5OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowe...
CVE-2026-22181HIGH7.6OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allows att...
CVE-2026-22179HIGH7.5OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows...
CVE-2026-22178HIGH8.2OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the str...
CVE-2026-22177HIGH8.8OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars...
CVE-2026-22175HIGH7.1OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always ...
CVE-2026-22169HIGH7.1OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows...
CVE-2026-22168HIGH8.8OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows auth...
CVE-2026-28674HIGH7.2xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin...
CVE-2026-28673HIGH7.2xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now