2026 CVE Vulnerabilities

64,824 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-43579MEDIUM6.5OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that...
CVE-2026-43578CRITICAL9.1OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrad...
CVE-2026-43577HIGH7.1OpenClaw before 2026.4.9 contains a file read vulnerability allowing attackers to bypass navigation guards through brows...
CVE-2026-43576HIGH7.7OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoin...
CVE-2026-43575CRITICAL9.8OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper ...
CVE-2026-40326HIGH7.1Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the createBundle method in ...
CVE-2026-40325HIGH8.7Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the `cTrash.restore` functi...
CVE-2026-40309HIGH7.2Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cTrash.empty function d...
CVE-2026-40174HIGH7.1Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cUsers.updateAddress fu...
CVE-2026-40171HIGH8.4In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-...
CVE-2026-40076HIGH8.8OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8...
CVE-2026-33441——Rejected reason: This CVE is a duplicate of another CVE: CVE-2026-33079.
CVE-2026-8031MEDIUM5.5A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown func...
CVE-2026-8022LOW3.1Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a ...
CVE-2026-8021MEDIUM4.2Script injection in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage ...
CVE-2026-8020MEDIUM5.3Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromise...
CVE-2026-8019MEDIUM5.4Insufficient policy enforcement in WebApp in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform U...
CVE-2026-8018HIGH8.1Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potenti...
CVE-2026-8017LOW3.1Side-channel information leakage in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cros...
CVE-2026-8016HIGH8.8Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-8015MEDIUM5.4Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI sp...
CVE-2026-8014MEDIUM4.3Inappropriate implementation in Preload in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-...
CVE-2026-8013MEDIUM4.3Insufficient validation of untrusted input in FedCM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to...
CVE-2026-8012MEDIUM5.4Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromi...
CVE-2026-8011MEDIUM4.3Insufficient policy enforcement in Search in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cros...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now