2026 CVE Vulnerabilities
64,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7206 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | A security flaw has been discovered in dubydu sqlite-mcp up to 0.1.0. The affected element is the function extract_to_js... |
| CVE-2026-7205 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A vulnerability was identified in duartium papers-mcp-server 9ceb3812a6458ba7922ca24a7406f8807bc55598. Impacted is the f... |
| CVE-2026-7204 | CRITICAL | 9.8 | 2.4% | Apr 28, 2026 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg... |
| CVE-2026-7203 | CRITICAL | 9.8 | 2.4% | Apr 28, 2026 | A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterR... |
| CVE-2026-7202 | CRITICAL | 9.8 | 2.4% | Apr 28, 2026 | A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the... |
| CVE-2026-32649 | HIGH | 7.3 | 0.9% | Apr 28, 2026 | A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras. |
| CVE-2026-32644 | CRITICAL | 9.8 | 0.2% | Apr 28, 2026 | Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys. |
| CVE-2026-20766 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras. |
| CVE-2026-7200 | MEDIUM | 4.3 | 0.3% | Apr 28, 2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is some unknown ... |
| CVE-2026-7199 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability i... |
| CVE-2026-7196 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A security vulnerability has been detected in CodeAstro Online Classroom 1.0. Affected is an unknown function of the fil... |
| CVE-2026-41372 | MEDIUM | 6.9 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing byp... |
| CVE-2026-41371 | HIGH | 8.5 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway ca... |
| CVE-2026-41370 | HIGH | 7.1 | 0.4% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrar... |
| CVE-2026-41369 | HIGH | 7.1 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to fi... |
| CVE-2026-41368 | HIGH | 7.1 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails... |
| CVE-2026-41367 | MEDIUM | 5.3 | 0.2% | Apr 28, 2026 | OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord butto... |
| CVE-2026-41366 | MEDIUM | 6 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that all... |
| CVE-2026-41365 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph ... |
| CVE-2026-41364 | HIGH | 8.1 | 0.5% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attack... |
| CVE-2026-41363 | MEDIUM | 6.5 | 0.3% | Apr 28, 2026 | OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploa... |
| CVE-2026-41362 | MEDIUM | 4.3 | 0.3% | Apr 28, 2026 | OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation vulnerability in the Zalo webhook repla... |
| CVE-2026-40977 | MEDIUM | 6.7 | 0.1% | Apr 28, 2026 | When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file'... |
| CVE-2026-40976 | CRITICAL | 9.1 | 0.5% | Apr 28, 2026 | In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoint... |
| CVE-2026-40975 | HIGH | 7.5 | 0.3% | Apr 28, 2026 | Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} an... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now