2026 CVE Vulnerabilities

61,327 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-53815HIGH7.1OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allo...
CVE-2026-53814HIGH8.7OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly rece...
CVE-2026-53813HIGH7.8OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state ...
CVE-2026-53812HIGH7.7OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authentica...
CVE-2026-53811HIGH8.8OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authe...
CVE-2026-53810HIGH8.8OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redir...
CVE-2026-53809MEDIUM4.8OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using pr...
CVE-2026-53808MEDIUM6.5OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows a...
CVE-2026-53807HIGH8.8OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows au...
CVE-2026-53806HIGH8.8OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass...
CVE-2026-50245HIGH8.3Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is r...
CVE-2026-50005HIGH8.3Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera...
CVE-2026-41005CRITICAL9Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML s...
CVE-2026-53782HIGH7.4Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast...
CVE-2026-53781MEDIUM5.3Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhausti...
CVE-2026-49973CRITICAL9.4Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remot...
CVE-2026-49949MEDIUM6CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercep...
CVE-2026-46622HIGH8.1SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API...
CVE-2026-46489HIGH8.1SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any ...
CVE-2026-45802MEDIUM6FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as template...
CVE-2026-45175HIGH7.8Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent vali...
CVE-2026-12038Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-53702MEDIUM6.5A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buf...
CVE-2026-53701MEDIUM6.5An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad....
CVE-2026-52860HIGH7.8Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes recons...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now