2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7308 | MEDIUM | 5.4 | 0.3% | May 11, 2026 | An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript t... |
| CVE-2026-7210 | HIGH | 7.5 | 0.8% | May 11, 2026 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow... |
| CVE-2026-5266 | LOW | 2.3 | 0.2% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerabil... |
| CVE-2026-5172 | HIGH | 7.3 | 2.7% | May 11, 2026 | A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and ... |
| CVE-2026-4893 | MEDIUM | 5.3 | 2.7% | May 11, 2026 | An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS pac... |
| CVE-2026-4892 | HIGH | 8.4 | 0.8% | May 11, 2026 | A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute... |
| CVE-2026-4891 | MEDIUM | 5.3 | 6.4% | May 11, 2026 | A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a den... |
| CVE-2026-4890 | HIGH | 7.5 | 8.8% | May 11, 2026 | A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of... |
| CVE-2026-45006 | HIGH | 8.8 | 0.5% | May 11, 2026 | OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and confi... |
| CVE-2026-45005 | MEDIUM | 6 | 0.3% | May 11, 2026 | OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to re... |
| CVE-2026-45004 | HIGH | 8.4 | 0.1% | May 11, 2026 | OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that l... |
| CVE-2026-45003 | MEDIUM | 5 | 0.1% | May 11, 2026 | OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC... |
| CVE-2026-45002 | MEDIUM | 6.3 | 0.3% | May 11, 2026 | OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks... |
| CVE-2026-45001 | HIGH | 7.1 | 0.2% | May 11, 2026 | OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.appl... |
| CVE-2026-45000 | MEDIUM | 5 | 0.2% | May 11, 2026 | OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skip... |
| CVE-2026-44999 | MEDIUM | 6.3 | 0.2% | May 11, 2026 | OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webho... |
| CVE-2026-44998 | MEDIUM | 5.4 | 0.7% | May 11, 2026 | OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and LSP tools to circumvent c... |
| CVE-2026-44997 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to ... |
| CVE-2026-44996 | MEDIUM | 6.3 | 0.3% | May 11, 2026 | OpenClaw before 2026.4.15 contains an arbitrary local file read vulnerability in the webchat audio embedding helper that... |
| CVE-2026-44995 | HIGH | 7.3 | 0.1% | May 11, 2026 | OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configu... |
| CVE-2026-44994 | MEDIUM | 6.3 | 0.3% | May 11, 2026 | OpenClaw before 2026.4.22 contains an authentication bypass vulnerability in the Control UI bootstrap config endpoint th... |
| CVE-2026-44993 | MEDIUM | 5.4 | 0.3% | May 11, 2026 | OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassi... |
| CVE-2026-44992 | MEDIUM | 5 | 0.1% | May 11, 2026 | OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace d... |
| CVE-2026-44991 | MEDIUM | 4.2 | 0.2% | May 11, 2026 | OpenClaw before 2026.4.21 contains an authorization bypass vulnerability in command-auth.ts that allows non-owner sender... |
| CVE-2026-44777 | MEDIUM | 5.5 | 0.2% | May 11, 2026 | jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detectio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now