2026 CVE Vulnerabilities

65,007 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41329CRITICAL9.9OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbea...
CVE-2026-41303HIGH8.8OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in Discord text approval commands that allows n...
CVE-2026-41302MEDIUM6.3OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functi...
CVE-2026-41301MEDIUM6.9OpenClaw versions 2026.3.22 before 2026.3.31 contain a signature verification bypass vulnerability in the Nostr DM ingre...
CVE-2026-41300MEDIUM6.9OpenClaw before 2026.3.31 contains a trust-decline vulnerability that preserves attacker-discovered endpoints in remote ...
CVE-2026-41299HIGH7.1OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only ...
CVE-2026-41298MEDIUM5.4OpenClaw before 2026.4.2 fails to enforce write scopes on the POST /sessions/:sessionKey/kill endpoint in identity-beari...
CVE-2026-41297HIGH7.6OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functi...
CVE-2026-41296HIGH8.8OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile f...
CVE-2026-41295HIGH8.5OpenClaw before 2026.4.2 contains an improper trust boundary vulnerability allowing untrusted workspace channel shadows ...
CVE-2026-41294HIGH8.6OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing...
CVE-2026-41285MEDIUM4.3In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Dis...
CVE-2026-40045MEDIUM5.9OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials...
CVE-2026-35588MEDIUM6.3Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`g...
CVE-2026-35587HIGH8.8Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (...
CVE-2026-35570HIGH8.4OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to ...
CVE-2026-34839MEDIUM6.5Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes ...
CVE-2026-5721MEDIUM4.7The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stor...
CVE-2026-34082MEDIUM4.3Dify is an open-source LLM app development platform. Prior to 1.13.1, the method `DELETE /console/api/installed-apps/<ap...
CVE-2026-6729HIGH7.6HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated...
CVE-2026-29643HIGH7.1XiangShan (Open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) c...
CVE-2026-22051MEDIUM4.3StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Di...
CVE-2026-0930MEDIUM4.3Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated us...
CVE-2026-5928HIGH7.5Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between ...
CVE-2026-5450CRITICAL9.8Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now