2026 CVE Vulnerabilities
53,539 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22168 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows auth... |
| CVE-2026-28674 | HIGH | 7.2 | 0.3% | Mar 18, 2026 | xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin... |
| CVE-2026-28673 | HIGH | 7.2 | 0.6% | Mar 18, 2026 | xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin... |
| CVE-2026-27980 | HIGH | 7.5 | 0.7% | Mar 18, 2026 | Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 1... |
| CVE-2026-27979 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1... |
| CVE-2026-27895 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d... |
| CVE-2026-27894 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d... |
| CVE-2026-27811 | HIGH | 8.8 | 2.0% | Mar 18, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a comma... |
| CVE-2026-26001 | HIGH | 8.8 | 0.2% | Mar 18, 2026 | The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents... |
| CVE-2026-22727 | HIGH | 7.5 | 0.2% | Mar 17, 2026 | Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on a... |
| CVE-2026-32842 | HIGH | 7.1 | 0.2% | Mar 17, 2026 | Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows att... |
| CVE-2026-1376 | HIGH | 7.5 | 0.5% | Mar 17, 2026 | IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to impr... |
| CVE-2026-4358 | HIGH | 7.5 | 0.3% | Mar 17, 2026 | A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-fre... |
| CVE-2026-4295 | HIGH | 8.5 | 0.2% | Mar 17, 2026 | Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote una... |
| CVE-2026-4064 | HIGH | 8.3 | 0.3% | Mar 17, 2026 | Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authen... |
| CVE-2026-32981 | HIGH | 7.5 | 0.9% | Mar 17, 2026 | A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due t... |
| CVE-2026-30707 | HIGH | 8.1 | 0.3% | Mar 17, 2026 | An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control v... |
| CVE-2026-25936 | HIGH | 8.8 | 0.3% | Mar 17, 2026 | GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an auth... |
| CVE-2026-25790 | HIGH | 7.2 | 0.4% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 ... |
| CVE-2026-25772 | HIGH | 7.2 | 0.3% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 ... |
| CVE-2026-25771 | HIGH | 7.5 | 0.5% | Mar 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.3.0 ... |
| CVE-2026-22882 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2026-20726 | HIGH | 7.1 | 0.3% | Mar 17, 2026 | An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ... |
| CVE-2026-32296 | HIGH | 8.8 | 0.5% | Mar 17, 2026 | Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthent... |
| CVE-2026-32294 | HIGH | 7 | 0.1% | Mar 17, 2026 | JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a comp... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now