2026 CVE Vulnerabilities
44,976 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62233 | HIGH | 8.8 | 0.2% | Jul 17, 2026 | grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints... |
| CVE-2026-62231 | HIGH | 8.6 | 0.2% | Jul 17, 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created wit... |
| CVE-2026-62230 | HIGH | 8.7 | 0.3% | Jul 17, 2026 | Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access t... |
| CVE-2026-62229 | HIGH | 8.8 | 0.5% | Jul 17, 2026 | OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lowe... |
| CVE-2026-62228 | HIGH | 8.8 | 0.2% | Jul 17, 2026 | OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust ca... |
| CVE-2026-62227 | HIGH | 7.7 | 0.2% | Jul 17, 2026 | OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that ... |
| CVE-2026-62226 | HIGH | 8.5 | 0.3% | Jul 17, 2026 | OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to... |
| CVE-2026-62223 | HIGH | 8.8 | 0.3% | Jul 17, 2026 | OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows ... |
| CVE-2026-62222 | HIGH | 7.8 | 0.1% | Jul 17, 2026 | OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plu... |
| CVE-2026-62219 | HIGH | 7.1 | 0.2% | Jul 17, 2026 | OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validatio... |
| CVE-2026-62218 | HIGH | 8.8 | 0.3% | Jul 17, 2026 | OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature tha... |
| CVE-2026-62217 | HIGH | 8.8 | 0.2% | Jul 17, 2026 | OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the f... |
| CVE-2026-62215 | HIGH | 8 | 0.2% | Jul 17, 2026 | OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lo... |
| CVE-2026-62212 | HIGH | 7.1 | 0.2% | Jul 17, 2026 | OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected fea... |
| CVE-2026-62209 | HIGH | 8.1 | 0.2% | Jul 17, 2026 | OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch... |
| CVE-2026-62207 | HIGH | 8.8 | 0.3% | Jul 17, 2026 | OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reac... |
| CVE-2026-62206 | HIGH | 7.1 | 0.2% | Jul 17, 2026 | OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affect... |
| CVE-2026-62205 | HIGH | 7.1 | 0.2% | Jul 17, 2026 | OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message... |
| CVE-2026-62203 | HIGH | 8.8 | 0.3% | Jul 17, 2026 | OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to pro... |
| CVE-2026-62202 | HIGH | 8.8 | 0.3% | Jul 17, 2026 | OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allow... |
| CVE-2026-62201 | HIGH | 7.7 | 0.3% | Jul 17, 2026 | OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows l... |
| CVE-2026-40106 | HIGH | 7.8 | 0.1% | Jul 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above p... |
| CVE-2026-54340 | HIGH | 7.5 | 0.3% | Jul 17, 2026 | h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state am... |
| CVE-2026-39359 | HIGH | 7.5 | 0.2% | Jul 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through ... |
| CVE-2026-34150 | HIGH | 7.5 | 0.2% | Jul 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and abov... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now