2026 CVE Vulnerabilities
45,449 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28462 | CRITICAL | 9.1 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplie... |
| CVE-2026-28454 | CRITICAL | 9.8 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowin... |
| CVE-2026-28453 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal... |
| CVE-2026-28451 | CRITICAL | 9.3 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain server-side request forgery vulnerabilities in the Feishu extension that al... |
| CVE-2026-28448 | CRITICAL | 9.4 | 0.4% | Mar 5, 2026 | OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enable... |
| CVE-2026-28446 | CRITICAL | 9.8 | 0.7% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass... |
| CVE-2026-28395 | CRITICAL | 9.1 | 0.4% | Mar 5, 2026 | OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extensi... |
| CVE-2026-28393 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading... |
| CVE-2026-28392 | CRITICAL | 9.8 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler tha... |
| CVE-2026-28391 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec req... |
| CVE-2026-21622 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows... |
| CVE-2026-28443 | CRITICAL | 9.8 | 0.3% | Mar 5, 2026 | OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint h... |
| CVE-2026-0848 | CRITICAL | 10 | 0.8% | Mar 5, 2026 | NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegment... |
| CVE-2026-28353 | CRITICAL | 10 | 0.5% | Mar 5, 2026 | Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.... |
| CVE-2026-27944 | CRITICAL | 9.8 | 22.2% | Mar 5, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessibl... |
| CVE-2026-25921 | CRITICAL | 9.3 | 0.3% | Mar 5, 2026 | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos ... |
| CVE-2026-24457 | CRITICAL | 9.8 | 0.6% | Mar 5, 2026 | An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbit... |
| CVE-2026-30793 | CRITICAL | 9.8 | 0.3% | Mar 5, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Li... |
| CVE-2026-30789 | CRITICAL | 9.8 | 0.3% | Mar 5, 2026 | Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts v... |
| CVE-2026-30783 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Cl... |
| CVE-2026-2599 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in ... |
| CVE-2026-21628 | CRITICAL | 9.8 | 0.5% | Mar 5, 2026 | A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading t... |
| CVE-2026-2743 | CRITICAL | 9.8 | 0.8% | Mar 5, 2026 | Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected fea... |
| CVE-2026-25702 | CRITICAL | 9.8 | 0.2% | Mar 5, 2026 | A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causi... |
| CVE-2026-1678 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cac... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now