2026 CVE Vulnerabilities
61,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54095 | — | — | — | Jun 12, 2026 | Rejected reason: CVE ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-53826. Reason: This candidate i... |
| CVE-2026-53868 | HIGH | 8.7 | 0.3% | Jun 12, 2026 | Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary... |
| CVE-2026-53867 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remo... |
| CVE-2026-53839 | MEDIUM | 6.5 | 0.3% | Jun 12, 2026 | OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching host... |
| CVE-2026-53838 | CRITICAL | 9.8 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes ... |
| CVE-2026-53837 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to va... |
| CVE-2026-53836 | HIGH | 8.8 | 0.5% | Jun 12, 2026 | OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows ... |
| CVE-2026-53835 | MEDIUM | 4.3 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that... |
| CVE-2026-53834 | MEDIUM | 6.5 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allow... |
| CVE-2026-53833 | MEDIUM | 6.5 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows auth... |
| CVE-2026-53832 | HIGH | 7.1 | 0.1% | Jun 12, 2026 | OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge... |
| CVE-2026-53831 | HIGH | 8.1 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that a... |
| CVE-2026-53830 | MEDIUM | 6.5 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and ... |
| CVE-2026-53829 | HIGH | 8.5 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide com... |
| CVE-2026-53828 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authentic... |
| CVE-2026-53827 | MEDIUM | 6.5 | 0.3% | Jun 12, 2026 | OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-con... |
| CVE-2026-53826 | MEDIUM | 4.3 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spawning that exposes th... |
| CVE-2026-53825 | HIGH | 7.1 | 0.4% | Jun 12, 2026 | OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows aut... |
| CVE-2026-53824 | MEDIUM | 6.5 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to contin... |
| CVE-2026-53823 | HIGH | 8.6 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Sl... |
| CVE-2026-53822 | HIGH | 8.8 | 1.0% | Jun 12, 2026 | OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between appro... |
| CVE-2026-53821 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or... |
| CVE-2026-53820 | MEDIUM | 6.9 | 0.1% | Jun 12, 2026 | OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path t... |
| CVE-2026-53609 | CRITICAL | 9.1 | 0.2% | Jun 12, 2026 | ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.se... |
| CVE-2026-53608 | HIGH | 8.7 | 0.2% | Jun 12, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostroph... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now