2026 CVE Vulnerabilities
61,327 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53815 | HIGH | 7.1 | 0.2% | Jun 11, 2026 | OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allo... |
| CVE-2026-53814 | HIGH | 8.7 | 0.3% | Jun 11, 2026 | OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly rece... |
| CVE-2026-53813 | HIGH | 7.8 | 0.1% | Jun 11, 2026 | OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state ... |
| CVE-2026-53812 | HIGH | 7.7 | 0.2% | Jun 11, 2026 | OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authentica... |
| CVE-2026-53811 | HIGH | 8.8 | 0.3% | Jun 11, 2026 | OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authe... |
| CVE-2026-53810 | HIGH | 8.8 | 0.4% | Jun 11, 2026 | OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redir... |
| CVE-2026-53809 | MEDIUM | 4.8 | 0.1% | Jun 11, 2026 | OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using pr... |
| CVE-2026-53808 | MEDIUM | 6.5 | 0.2% | Jun 11, 2026 | OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows a... |
| CVE-2026-53807 | HIGH | 8.8 | 0.3% | Jun 11, 2026 | OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows au... |
| CVE-2026-53806 | HIGH | 8.8 | 0.4% | Jun 11, 2026 | OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass... |
| CVE-2026-50245 | HIGH | 8.3 | 0.2% | Jun 11, 2026 | Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is r... |
| CVE-2026-50005 | HIGH | 8.3 | 0.2% | Jun 11, 2026 | Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera... |
| CVE-2026-41005 | CRITICAL | 9 | 0.1% | Jun 11, 2026 | Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML s... |
| CVE-2026-53782 | HIGH | 7.4 | 0.3% | Jun 11, 2026 | Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast... |
| CVE-2026-53781 | MEDIUM | 5.3 | 0.3% | Jun 11, 2026 | Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhausti... |
| CVE-2026-49973 | CRITICAL | 9.4 | 0.5% | Jun 11, 2026 | Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remot... |
| CVE-2026-49949 | MEDIUM | 6 | 0.3% | Jun 11, 2026 | CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercep... |
| CVE-2026-46622 | HIGH | 8.1 | 0.2% | Jun 11, 2026 | SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API... |
| CVE-2026-46489 | HIGH | 8.1 | 0.3% | Jun 11, 2026 | SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any ... |
| CVE-2026-45802 | MEDIUM | 6 | 0.3% | Jun 11, 2026 | FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as template... |
| CVE-2026-45175 | HIGH | 7.8 | 0.1% | Jun 11, 2026 | Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent vali... |
| CVE-2026-12038 | — | — | — | Jun 11, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-53702 | MEDIUM | 6.5 | 0.2% | Jun 11, 2026 | A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buf... |
| CVE-2026-53701 | MEDIUM | 6.5 | 0.2% | Jun 11, 2026 | An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad.... |
| CVE-2026-52860 | HIGH | 7.8 | 0.2% | Jun 11, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes recons... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now