2026 CVE Vulnerabilities

44,976 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-62233HIGH8.8grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints...
CVE-2026-62231HIGH8.6The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created wit...
CVE-2026-62230HIGH8.7Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access t...
CVE-2026-62229HIGH8.8OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lowe...
CVE-2026-62228HIGH8.8OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust ca...
CVE-2026-62227HIGH7.7OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that ...
CVE-2026-62226HIGH8.5OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to...
CVE-2026-62223HIGH8.8OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows ...
CVE-2026-62222HIGH7.8OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plu...
CVE-2026-62219HIGH7.1OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validatio...
CVE-2026-62218HIGH8.8OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature tha...
CVE-2026-62217HIGH8.8OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the f...
CVE-2026-62215HIGH8OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lo...
CVE-2026-62212HIGH7.1OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected fea...
CVE-2026-62209HIGH8.1OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch...
CVE-2026-62207HIGH8.8OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reac...
CVE-2026-62206HIGH7.1OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affect...
CVE-2026-62205HIGH7.1OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message...
CVE-2026-62203HIGH8.8OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to pro...
CVE-2026-62202HIGH8.8OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allow...
CVE-2026-62201HIGH7.7OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows l...
CVE-2026-40106HIGH7.8Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above p...
CVE-2026-54340HIGH7.5h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state am...
CVE-2026-39359HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through ...
CVE-2026-34150HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and abov...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now