2026 CVE Vulnerabilities

56,052 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-26316HIGH7.5OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept w...
CVE-2026-26315HIGH7.5go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through...
CVE-2026-26314HIGH7.5go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulne...
CVE-2026-26275HIGH7.5httpsig-hyper is a hyper extension for http message signatures. An issue was discovered in `httpsig-hyper` prior to vers...
CVE-2026-27343HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27114HIGH7.5NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOf...
CVE-2026-26313HIGH7.5go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an atta...
CVE-2026-26286HIGH8.5SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-26318HIGH8.8systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command...
CVE-2026-26280HIGH7.8systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection v...
CVE-2026-26278HIGH7.5fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li...
CVE-2026-26267HIGH7.5soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` ma...
CVE-2026-26205HIGH7.1opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability i...
CVE-2026-26202HIGH7.5Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user c...
CVE-2026-26201HIGH7.5emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 3.21.2, multiple shared maps are access...
CVE-2026-26200HIGH7.8HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 c...
CVE-2026-26189HIGH8.1Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulne...
CVE-2026-26063HIGH8.8CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attack...
CVE-2026-26337HIGH8.8Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-s...
CVE-2026-2232HIGH7.5The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection v...
CVE-2026-26336HIGH8.7Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via t...
CVE-2026-26016HIGH8.1Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1....
CVE-2026-25998HIGH7.5strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the datab...
CVE-2026-24834HIGH8.8Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2026-1581HIGH7.5The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all version...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now