2026 CVE Vulnerabilities

64,952 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31953MEDIUM5.4Xibo is an open source digital signage platform with a web content management system and Windows display player software...
CVE-2026-40630CRITICAL9.8A vulnerability in  SenseLive X3050’s web management interface allows unauthorized access to certain configuration end...
CVE-2026-40623HIGH8.1A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameter...
CVE-2026-40620CRITICAL9.8A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established wi...
CVE-2026-40431MEDIUM6.9A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all adm...
CVE-2026-39462CRITICAL9.3A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied ...
CVE-2026-35503CRITICAL9.8A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on th...
CVE-2026-35064HIGH8.7A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the...
CVE-2026-31952HIGH8.1Xibo is an open source digital signage platform with a web content management system and Windows display player software...
CVE-2026-29197MEDIUM4.3In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/log...
CVE-2026-29051LOW3.3melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version ...
CVE-2026-29050MEDIUM6.1melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version ...
CVE-2026-27843CRITICAL9.2A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be...
CVE-2026-27841HIGH8.4A vulnerability in SenseLive X3050's web management interface allows state-changing operations to be triggered without p...
CVE-2026-25775CRITICAL9.8A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be per...
CVE-2026-25720MEDIUM5.4A vulnerability exists in SenseLive X3050’s web management interface due to improper session lifetime enforcement, allo...
CVE-2026-1789MEDIUM6.9A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive informat...
CVE-2026-6732HIGH7.5A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definit...
CVE-2026-41361HIGH7.1OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 special-use ranges. ...
CVE-2026-41360MEDIUM6.7OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operan...
CVE-2026-41359HIGH8.8OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write perm...
CVE-2026-41358MEDIUM5.4OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to ...
CVE-2026-41357LOW3.3OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbox backends that pass...
CVE-2026-41356MEDIUM5.4OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previ...
CVE-2026-41355HIGH7.3OpenClaw before 2026.3.28 contains an arbitrary code execution vulnerability in mirror mode that converts untrusted sand...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now