2026 CVE Vulnerabilities

66,764 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32970LOW3.3OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and ga...
CVE-2026-32921MEDIUM5OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not b...
CVE-2026-32920HIGH8.8OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust ve...
CVE-2026-32917CRITICAL9.8OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that...
CVE-2026-32916CRITICAL9.8OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes e...
CVE-2026-27854HIGH7.5An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:...
CVE-2026-27853HIGH7.5An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQ...
CVE-2026-24030HIGH7.5An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HT...
CVE-2026-24029MEDIUM6.5When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using...
CVE-2026-24028HIGH8.2An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua cod...
CVE-2026-0397MEDIUM4.3When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged...
CVE-2026-0396MEDIUM4.3An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNS...
CVE-2026-4400MEDIUM6.5Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot Millie chat that allows private conversations of ot...
CVE-2026-4399HIGH7.5Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions ...
CVE-2026-34887MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubi...
CVE-2026-5197MEDIUM6.3A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of...
CVE-2026-4317CRITICAL9.3SQL inyection (SQLi) vulnerability in Umami Software web application through an improperly sanitized parameter, which co...
CVE-2026-5201HIGH7.5A flaw was found in the gdk-pixbuf library. This heap-based buffer overflow vulnerability occurs in the JPEG image loade...
CVE-2026-5196MEDIUM6.3A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the fi...
CVE-2026-5195HIGH7.3A flaw has been found in code-projects Student Membership System 1.0. This issue affects some unknown processing of the ...
CVE-2026-3107MEDIUM5.4Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password impo...
CVE-2026-3106MEDIUM5.4Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionalit...
CVE-2026-5186MEDIUM5.3A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb...
CVE-2026-5185MEDIUM5.3A security flaw has been discovered in Nothings stb_image up to 2.30. This affects the function stbi__gif_load_next of t...
CVE-2026-5184HIGH8.8A vulnerability was identified in TRENDnet TEW-713RE up to 1.02. The impacted element is an unknown function of the file...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now