2026 CVE Vulnerabilities

53,539 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-22168HIGH8.8OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows auth...
CVE-2026-28674HIGH7.2xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin...
CVE-2026-28673HIGH7.2xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin...
CVE-2026-27980HIGH7.5Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 1...
CVE-2026-27979HIGH7.5Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1...
CVE-2026-27895HIGH8.8LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d...
CVE-2026-27894HIGH8.8LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d...
CVE-2026-27811HIGH8.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a comma...
CVE-2026-26001HIGH8.8The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents...
CVE-2026-22727HIGH7.5Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on a...
CVE-2026-32842HIGH7.1Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows att...
CVE-2026-1376HIGH7.5IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to impr...
CVE-2026-4358HIGH7.5A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-fre...
CVE-2026-4295HIGH8.5Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote una...
CVE-2026-4064HIGH8.3Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authen...
CVE-2026-32981HIGH7.5A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due t...
CVE-2026-30707HIGH8.1An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control v...
CVE-2026-25936HIGH8.8GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an auth...
CVE-2026-25790HIGH7.2Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 ...
CVE-2026-25772HIGH7.2Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 ...
CVE-2026-25771HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.3.0 ...
CVE-2026-22882HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2026-20726HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2026-32296HIGH8.8Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthent...
CVE-2026-32294HIGH7JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a comp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now