2026 CVE Vulnerabilities
64,824 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3291 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated vers... |
| CVE-2026-40332 | MEDIUM | 5.3 | 0.3% | May 6, 2026 | Masa CMS is affected by an Open Redirect vulnerability due to improper handling of scheme-relative URLs. The application... |
| CVE-2026-40281 | CRITICAL | 9.1 | 0.6% | May 6, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint v... |
| CVE-2026-40251 | MEDIUM | 6.5 | 0.4% | May 6, 2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora... |
| CVE-2026-40243 | MEDIUM | 4.8 | 0.2% | May 6, 2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OV... |
| CVE-2026-40197 | MEDIUM | 6.5 | 0.3% | May 6, 2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora... |
| CVE-2026-40195 | MEDIUM | 6.5 | 0.4% | May 6, 2026 | Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the stora... |
| CVE-2026-8033 | MEDIUM | 5.5 | 0.3% | May 6, 2026 | A vulnerability has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. This affects an unknown function of t... |
| CVE-2026-8032 | HIGH | 7.3 | 0.3% | May 6, 2026 | A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of... |
| CVE-2026-44118 | HIGH | 8.5 | 0.1% | May 6, 2026 | OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request heade... |
| CVE-2026-44117 | MEDIUM | 6.3 | 0.2% | May 6, 2026 | OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips U... |
| CVE-2026-44116 | HIGH | 8.6 | 0.3% | May 6, 2026 | OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function t... |
| CVE-2026-44115 | HIGH | 8.8 | 0.4% | May 6, 2026 | OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted ... |
| CVE-2026-44114 | HIGH | 8.5 | 0.1% | May 6, 2026 | OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dot... |
| CVE-2026-44113 | HIGH | 8.3 | 0.2% | May 6, 2026 | OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that al... |
| CVE-2026-44112 | CRITICAL | 9.6 | 2.4% | May 6, 2026 | OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes tha... |
| CVE-2026-44111 | MEDIUM | 4.3 | 0.2% | May 6, 2026 | OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the QMD backend memory_get function that allo... |
| CVE-2026-44110 | HIGH | 8.8 | 0.3% | May 6, 2026 | OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization th... |
| CVE-2026-44109 | CRITICAL | 9.8 | 0.7% | May 6, 2026 | OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation t... |
| CVE-2026-43585 | CRITICAL | 9.8 | 0.5% | May 6, 2026 | OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain vali... |
| CVE-2026-43584 | HIGH | 8.8 | 0.4% | May 6, 2026 | OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment p... |
| CVE-2026-43583 | MEDIUM | 6.5 | 0.2% | May 6, 2026 | OpenClaw versions 2026.4.10 before 2026.4.14 fail to persist session context during delivery queue recovery for media re... |
| CVE-2026-43582 | MEDIUM | 6.3 | 0.2% | May 6, 2026 | OpenClaw before 2026.4.10 contains a server-side request forgery vulnerability in browser navigation policy that allows ... |
| CVE-2026-43581 | CRITICAL | 9.6 | 0.2% | May 6, 2026 | OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that expos... |
| CVE-2026-43580 | HIGH | 7.7 | 0.3% | May 6, 2026 | OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now