2026 CVE Vulnerabilities

64,909 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7206HIGH7.3A security flaw has been discovered in dubydu sqlite-mcp up to 0.1.0. The affected element is the function extract_to_js...
CVE-2026-7205HIGH7.3A vulnerability was identified in duartium papers-mcp-server 9ceb3812a6458ba7922ca24a7406f8807bc55598. Impacted is the f...
CVE-2026-7204CRITICAL9.8A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg...
CVE-2026-7203CRITICAL9.8A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterR...
CVE-2026-7202CRITICAL9.8A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the...
CVE-2026-32649HIGH7.3A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras.
CVE-2026-32644CRITICAL9.8Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.
CVE-2026-20766HIGH8.8An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.
CVE-2026-7200MEDIUM4.3A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is some unknown ...
CVE-2026-7199HIGH7.3A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability i...
CVE-2026-7196MEDIUM6.3A security vulnerability has been detected in CodeAstro Online Classroom 1.0. Affected is an unknown function of the fil...
CVE-2026-41372MEDIUM6.9OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing byp...
CVE-2026-41371HIGH8.5OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway ca...
CVE-2026-41370HIGH7.1OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrar...
CVE-2026-41369HIGH7.1OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to fi...
CVE-2026-41368HIGH7.1OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails...
CVE-2026-41367MEDIUM5.3OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord butto...
CVE-2026-41366MEDIUM6OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that all...
CVE-2026-41365MEDIUM5.4OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph ...
CVE-2026-41364HIGH8.1OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attack...
CVE-2026-41363MEDIUM6.5OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploa...
CVE-2026-41362MEDIUM4.3OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation vulnerability in the Zalo webhook repla...
CVE-2026-40977MEDIUM6.7When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file'...
CVE-2026-40976CRITICAL9.1In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoint...
CVE-2026-40975HIGH7.5Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} an...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now