2026 CVE Vulnerabilities
45,056 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44112 | CRITICAL | 9.6 | 2.4% | May 6, 2026 | OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes tha... |
| CVE-2026-44109 | CRITICAL | 9.8 | 0.7% | May 6, 2026 | OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation t... |
| CVE-2026-43585 | CRITICAL | 9.8 | 0.5% | May 6, 2026 | OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain vali... |
| CVE-2026-43581 | CRITICAL | 9.6 | 0.2% | May 6, 2026 | OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that expos... |
| CVE-2026-43578 | CRITICAL | 9.1 | 0.3% | May 6, 2026 | OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrad... |
| CVE-2026-43575 | CRITICAL | 9.8 | 0.4% | May 6, 2026 | OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper ... |
| CVE-2026-7910 | CRITICAL | 9.6 | 0.2% | May 6, 2026 | Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the render... |
| CVE-2026-7908 | CRITICAL | 9.6 | 0.2% | May 6, 2026 | Use after free in Fullscreen in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a ... |
| CVE-2026-41930 | CRITICAL | 9.8 | 0.3% | May 6, 2026 | Vvveb before version 1.0.8.2 contains a hard-coded credentials vulnerability in its docker-compose-apache.yaml configura... |
| CVE-2026-0300 | CRITICAL | 9.8 | 36.2% | May 6, 2026 | A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks... |
| CVE-2026-7875 | CRITICAL | 9.3 | 0.1% | May 6, 2026 | NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary vulnerability in outbound attachment hand... |
| CVE-2026-5081 | CRITICAL | 9.1 | 0.3% | May 6, 2026 | Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Sessi... |
| CVE-2026-43208 | CRITICAL | 9.8 | 0.5% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: do not pass flow_id to set_rps_cpu() Blamed c... |
| CVE-2026-43198 | CRITICAL | 9.8 | 0.3% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() ... |
| CVE-2026-43197 | CRITICAL | 9.1 | 0.5% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-termina... |
| CVE-2026-43186 | CRITICAL | 9.8 | 0.6% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fil... |
| CVE-2026-43185 | CRITICAL | 9.8 | 0.6% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix signededness bug in smb_direct_prepare_n... |
| CVE-2026-43125 | CRITICAL | 9.8 | 0.4% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The le... |
| CVE-2026-43117 | CRITICAL | 9.1 | 0.4% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct superblock from den... |
| CVE-2026-43114 | CRITICAL | 9.4 | 0.4% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo_avx2: don't return non-ma... |
| CVE-2026-43083 | CRITICAL | 9.1 | 0.4% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->t... |
| CVE-2026-40010 | CRITICAL | 9.1 | 0.4% | May 6, 2026 | Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a sessi... |
| CVE-2026-28780 | CRITICAL | 9.8 | 1.4% | May 5, 2026 | Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a maliciou... |
| CVE-2026-35579 | CRITICAL | 9.8 | 0.5% | May 5, 2026 | CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementati... |
| CVE-2026-40331 | CRITICAL | 9.3 | 0.3% | May 5, 2026 | Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 throu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now