2026 CVE Vulnerabilities
64,824 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43579 | MEDIUM | 6.5 | 0.2% | May 6, 2026 | OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that... |
| CVE-2026-43578 | CRITICAL | 9.1 | 0.3% | May 6, 2026 | OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrad... |
| CVE-2026-43577 | HIGH | 7.1 | 0.3% | May 6, 2026 | OpenClaw before 2026.4.9 contains a file read vulnerability allowing attackers to bypass navigation guards through brows... |
| CVE-2026-43576 | HIGH | 7.7 | 0.3% | May 6, 2026 | OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoin... |
| CVE-2026-43575 | CRITICAL | 9.8 | 0.4% | May 6, 2026 | OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper ... |
| CVE-2026-40326 | HIGH | 7.1 | 0.2% | May 6, 2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the createBundle method in ... |
| CVE-2026-40325 | HIGH | 8.7 | 0.2% | May 6, 2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the `cTrash.restore` functi... |
| CVE-2026-40309 | HIGH | 7.2 | 0.2% | May 6, 2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cTrash.empty function d... |
| CVE-2026-40174 | HIGH | 7.1 | 0.2% | May 6, 2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cUsers.updateAddress fu... |
| CVE-2026-40171 | HIGH | 8.4 | 0.5% | May 6, 2026 | In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-... |
| CVE-2026-40076 | HIGH | 8.8 | 0.9% | May 6, 2026 | OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8... |
| CVE-2026-33441 | — | — | — | May 6, 2026 | Rejected reason: This CVE is a duplicate of another CVE: CVE-2026-33079. |
| CVE-2026-8031 | MEDIUM | 5.5 | 0.4% | May 6, 2026 | A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown func... |
| CVE-2026-8022 | LOW | 3.1 | 0.2% | May 6, 2026 | Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a ... |
| CVE-2026-8021 | MEDIUM | 4.2 | 0.2% | May 6, 2026 | Script injection in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage ... |
| CVE-2026-8020 | MEDIUM | 5.3 | 0.2% | May 6, 2026 | Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromise... |
| CVE-2026-8019 | MEDIUM | 5.4 | 0.2% | May 6, 2026 | Insufficient policy enforcement in WebApp in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform U... |
| CVE-2026-8018 | HIGH | 8.1 | 0.3% | May 6, 2026 | Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potenti... |
| CVE-2026-8017 | LOW | 3.1 | 0.1% | May 6, 2026 | Side-channel information leakage in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cros... |
| CVE-2026-8016 | HIGH | 8.8 | 0.3% | May 6, 2026 | Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-8015 | MEDIUM | 5.4 | 0.2% | May 6, 2026 | Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI sp... |
| CVE-2026-8014 | MEDIUM | 4.3 | 0.2% | May 6, 2026 | Inappropriate implementation in Preload in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-... |
| CVE-2026-8013 | MEDIUM | 4.3 | 0.2% | May 6, 2026 | Insufficient validation of untrusted input in FedCM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to... |
| CVE-2026-8012 | MEDIUM | 5.4 | 0.1% | May 6, 2026 | Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromi... |
| CVE-2026-8011 | MEDIUM | 4.3 | 0.2% | May 6, 2026 | Insufficient policy enforcement in Search in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cros... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now