2026 CVE Vulnerabilities

65,328 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35653HIGH8.1OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that all...
CVE-2026-35652CRITICAL9.1OpenClaw before 2026.3.22 contains an authorization bypass vulnerability in interactive callback dispatch that allows no...
CVE-2026-35651MEDIUM5.3OpenClaw versions 2026.2.13 through 2026.3.24 contain an ANSI escape sequence injection vulnerability in approval prompt...
CVE-2026-35650HIGH8.8OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypa...
CVE-2026-35649MEDIUM6.5OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to bypass intended deny...
CVE-2026-35648MEDIUM5.9OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against c...
CVE-2026-35647MEDIUM6.9OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass DM policy checks an...
CVE-2026-35643HIGH8.8OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject...
CVE-2026-35641HIGH7.8OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that ...
CVE-2026-35621HIGH7.1OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command fails to re-validat...
CVE-2026-35620MEDIUM5.4OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handle...
CVE-2026-35619MEDIUM5.3OpenClaw before 2026.3.24 contains an authorization bypass vulnerability in the HTTP /v1/models endpoint that fails to e...
CVE-2026-35602HIGH7.1Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses th...
CVE-2026-35601MEDIUM4.1Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV output generator builds iCale...
CVE-2026-35600MEDIUM5.4Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, task titles are embedded directly into M...
CVE-2026-35599MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function use...
CVE-2026-35598MEDIUM4.3Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesB...
CVE-2026-35597HIGH7.5Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the TOTP failed-attempt lockout mechanis...
CVE-2026-35596MEDIUM4.3Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the hasAccessToLabel function contains a...
CVE-2026-35595HIGH8.3Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/projec...
CVE-2026-22560MEDIUM5.3An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by...
CVE-2026-40228LOW3.3In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p em...
CVE-2026-40227MEDIUM5.5In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that...
CVE-2026-40226MEDIUM6.4In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file.
CVE-2026-40225MEDIUM6.4In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel outp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now