2026 CVE Vulnerabilities

45,449 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-28462CRITICAL9.1OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplie...
CVE-2026-28454CRITICAL9.8OpenClaw versions prior to 2026.2.2 fail to validate webhook secrets in Telegram webhook mode (must be enabled), allowin...
CVE-2026-28453CRITICAL9.8OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal...
CVE-2026-28451CRITICAL9.3OpenClaw versions prior to 2026.2.14 contain server-side request forgery vulnerabilities in the Feishu extension that al...
CVE-2026-28448CRITICAL9.4OpenClaw versions 2026.1.29 prior to 2026.2.1 contain a vulnerability in the Twitch plugin (must be installed and enable...
CVE-2026-28446CRITICAL9.8OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass...
CVE-2026-28395CRITICAL9.1OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extensi...
CVE-2026-28393CRITICAL9.8OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading...
CVE-2026-28392CRITICAL9.8OpenClaw versions prior to 2026.2.14 contain a privilege escalation vulnerability in the Slack slash-command handler tha...
CVE-2026-28391CRITICAL9.8OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec req...
CVE-2026-21622CRITICAL9.8Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows...
CVE-2026-28443CRITICAL9.8OpenReplay is a self-hosted session replay suite. Prior to version 1.20.0, the POST /{projectId}/cards/search endpoint h...
CVE-2026-0848CRITICAL10NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegment...
CVE-2026-28353CRITICAL10Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1....
CVE-2026-27944CRITICAL9.8Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessibl...
CVE-2026-25921CRITICAL9.3Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos ...
CVE-2026-24457CRITICAL9.8An unsafe parsing of OpenMQ's configuration in OpenMQ versions <6.5.2 and <6.9.0, allows a remote attacker to read arbit...
CVE-2026-30793CRITICAL9.8Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Li...
CVE-2026-30789CRITICAL9.8Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts v...
CVE-2026-30783CRITICAL9.8A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Cl...
CVE-2026-2599CRITICAL9.8The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in ...
CVE-2026-21628CRITICAL9.8A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading t...
CVE-2026-2743CRITICAL9.8Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected fea...
CVE-2026-25702CRITICAL9.8A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causi...
CVE-2026-1678CRITICAL9.8dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cac...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now