2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-12511HIGH8.1The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downl...
CVE-2026-58233HIGH7.6SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted a...
CVE-2026-44752HIGH8.2SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted ...
CVE-2026-44745HIGH8.1SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurati...
CVE-2026-0487HIGH8.4SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location...
CVE-2026-58486HIGH8.3HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was ...
CVE-2026-58101HIGH7.5Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2...
CVE-2026-57856HIGH8.8Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() meth...
CVE-2026-57855HIGH8.8Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api...
CVE-2026-62328HIGH8.79Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attack...
CVE-2026-62242HIGH8.6Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated a...
CVE-2026-62240HIGH8.3CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one...
CVE-2026-62200HIGH8.8OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport t...
CVE-2026-62199HIGH8.8OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup va...
CVE-2026-62197HIGH8.5OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket ...
CVE-2026-62196HIGH8.7OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can s...
CVE-2026-62195HIGH8.7OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature th...
CVE-2026-62194HIGH8.8OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that...
CVE-2026-62192HIGH8.1OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that a...
CVE-2026-62191HIGH7.1OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling th...
CVE-2026-62190HIGH8.8OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-t...
CVE-2026-62189HIGH7.6OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower...
CVE-2026-62188HIGH8.6OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Fe...
CVE-2026-62187HIGH8.6OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A low...
CVE-2026-62186HIGH7.6OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model override...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now