2026 CVE Vulnerabilities

64,824 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3291MEDIUM5.5Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated vers...
CVE-2026-40332MEDIUM5.3Masa CMS is affected by an Open Redirect vulnerability due to improper handling of scheme-relative URLs. The application...
CVE-2026-40281CRITICAL9.1Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint v...
CVE-2026-40251MEDIUM6.5Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora...
CVE-2026-40243MEDIUM4.8Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OV...
CVE-2026-40197MEDIUM6.5Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora...
CVE-2026-40195MEDIUM6.5Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora...
CVE-2026-8033MEDIUM5.5A vulnerability has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. This affects an unknown function of t...
CVE-2026-8032HIGH7.3A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of...
CVE-2026-44118HIGH8.5OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request heade...
CVE-2026-44117MEDIUM6.3OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips U...
CVE-2026-44116HIGH8.6OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function t...
CVE-2026-44115HIGH8.8OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted ...
CVE-2026-44114HIGH8.5OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dot...
CVE-2026-44113HIGH8.3OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that al...
CVE-2026-44112CRITICAL9.6OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes tha...
CVE-2026-44111MEDIUM4.3OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the QMD backend memory_get function that allo...
CVE-2026-44110HIGH8.8OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization th...
CVE-2026-44109CRITICAL9.8OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation t...
CVE-2026-43585CRITICAL9.8OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain vali...
CVE-2026-43584HIGH8.8OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment p...
CVE-2026-43583MEDIUM6.5OpenClaw versions 2026.4.10 before 2026.4.14 fail to persist session context during delivery queue recovery for media re...
CVE-2026-43582MEDIUM6.3OpenClaw before 2026.4.10 contains a server-side request forgery vulnerability in browser navigation policy that allows ...
CVE-2026-43581CRITICAL9.6OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that expos...
CVE-2026-43580HIGH7.7OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now