2026 CVE Vulnerabilities
55,551 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25888 | HIGH | 8.8 | 0.7% | Mar 6, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-25887 | HIGH | 7.2 | 0.8% | Mar 6, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-29046 | HIGH | 8.2 | 0.4% | Mar 6, 2026 | TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header... |
| CVE-2026-29041 | HIGH | 8.8 | 0.7% | Mar 6, 2026 | Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote co... |
| CVE-2026-28502 | HIGH | 8.8 | 0.7% | Mar 6, 2026 | WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulner... |
| CVE-2026-3613 | HIGH | 7.3 | 0.7% | Mar 6, 2026 | A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the ... |
| CVE-2026-3612 | HIGH | 7.3 | 9.5% | Mar 6, 2026 | A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/... |
| CVE-2026-28727 | HIGH | 7.8 | 0.1% | Mar 6, 2026 | Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber P... |
| CVE-2026-28722 | HIGH | 7.3 | 0.2% | Mar 6, 2026 | Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec... |
| CVE-2026-28721 | HIGH | 7.3 | 0.2% | Mar 6, 2026 | Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec... |
| CVE-2026-28718 | HIGH | 7.5 | 0.3% | Mar 6, 2026 | Denial of service due to insufficient input validation in authentication logging. The following products are affected: A... |
| CVE-2026-28713 | HIGH | 7.1 | 0.2% | Mar 6, 2026 | Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyb... |
| CVE-2026-27778 | HIGH | 8.7 | 0.6% | Mar 6, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc... |
| CVE-2026-24912 | HIGH | 8.6 | 0.4% | Mar 6, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ... |
| CVE-2026-29613 | HIGH | 8.2 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in whi... |
| CVE-2026-29612 | HIGH | 7.5 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget... |
| CVE-2026-29611 | HIGH | 8.2 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be inst... |
| CVE-2026-29610 | HIGH | 8.8 | 0.5% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintend... |
| CVE-2026-29609 | HIGH | 8.7 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the fetchWithGuard function that alloc... |
| CVE-2026-28485 | HIGH | 7.8 | 0.2% | Mar 5, 2026 | OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control... |
| CVE-2026-28482 | HIGH | 8.4 | 0.1% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.12 construct transcript file paths using unsanitized sessionId parameters and sessionF... |
| CVE-2026-28481 | HIGH | 7.5 | 0.3% | Mar 5, 2026 | OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS... |
| CVE-2026-28478 | HIGH | 8.7 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request b... |
| CVE-2026-28477 | HIGH | 7.1 | 0.1% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login f... |
| CVE-2026-28473 | HIGH | 8.1 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scop... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now