2026 CVE Vulnerabilities

66,804 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34155MEDIUM5.3RAUC controls the update process on embedded Linux systems. Prior to version 1.15.2, RAUC bundles using the 'plain' form...
CVE-2026-30310CRITICAL9.8In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all ...
CVE-2026-5198HIGH7.3A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown functi...
CVE-2026-4267HIGH7.2The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site S...
CVE-2026-3191MEDIUM5.4The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2...
CVE-2026-3139MEDIUM4.3The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v...
CVE-2026-34509——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-34508——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-34506MEDIUM4.3OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unau...
CVE-2026-34505MEDIUM6.9OpenClaw before 2026.3.12 applies rate limiting only after successful webhook authentication, allowing attackers to bypa...
CVE-2026-32988HIGH7.5OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary fi...
CVE-2026-32982HIGH8.7OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes...
CVE-2026-32977MEDIUM6.3OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in the fs-bridge writeFile commit step that u...
CVE-2026-32976HIGH7.1OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing channel commands to mutate protected s...
CVE-2026-32971HIGH8OpenClaw before 2026.3.11 contains an approval-integrity vulnerability in node-host system.run approvals that displays e...
CVE-2026-32970LOW3.3OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and ga...
CVE-2026-32921MEDIUM5OpenClaw before 2026.3.8 contains an approval bypass vulnerability in system.run where mutable script operands are not b...
CVE-2026-32920HIGH8.8OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust ve...
CVE-2026-32917CRITICAL9.8OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that...
CVE-2026-32916CRITICAL9.8OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes e...
CVE-2026-27854HIGH7.5An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:...
CVE-2026-27853HIGH7.5An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQ...
CVE-2026-24030HIGH7.5An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HT...
CVE-2026-24029MEDIUM6.5When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using...
CVE-2026-24028HIGH8.2An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua cod...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now