2026 CVE Vulnerabilities
67,075 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4946 | HIGH | 8.8 | 0.4% | Mar 29, 2026 | Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data... |
| CVE-2026-0562 | HIGH | 8.3 | 0.3% | Mar 29, 2026 | A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or rej... |
| CVE-2026-0560 | HIGH | 7.5 | 1.8% | Mar 29, 2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in th... |
| CVE-2026-0558 | CRITICAL | 9.8 | 0.4% | Mar 29, 2026 | A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and proces... |
| CVE-2026-34005 | HIGH | 8.8 | 1.5% | Mar 29, 2026 | In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via s... |
| CVE-2026-5046 | HIGH | 8.8 | 0.6% | Mar 29, 2026 | A flaw has been found in Tenda FH1201 1.2.0.14(408). Affected is the function formWrlExtraSet of the file /goform/WrlExt... |
| CVE-2026-5045 | HIGH | 8.8 | 0.7% | Mar 29, 2026 | A vulnerability was detected in Tenda FH1201 1.2.0.14(408). This impacts the function WrlclientSet of the file /goform/W... |
| CVE-2026-5044 | HIGH | 8.8 | 0.7% | Mar 29, 2026 | A security vulnerability has been detected in Belkin F9K1122 1.00.33. This affects the function formSetSystemSettings of... |
| CVE-2026-33575 | HIGH | 8.6 | 0.2% | Mar 29, 2026 | OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pai... |
| CVE-2026-33574 | MEDIUM | 4.7 | 0.1% | Mar 29, 2026 | OpenClaw before 2026.3.8 contains a path traversal vulnerability in the skills download installer that validates the too... |
| CVE-2026-33573 | HIGH | 8.8 | 0.3% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authentica... |
| CVE-2026-33572 | MEDIUM | 5.5 | 0.1% | Mar 29, 2026 | OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local u... |
| CVE-2026-32987 | CRITICAL | 9.8 | 0.4% | Mar 29, 2026 | OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/de... |
| CVE-2026-32980 | HIGH | 8.7 | 0.5% | Mar 29, 2026 | OpenClaw before 2026.3.13 reads and buffers Telegram webhook request bodies before validating the x-telegram-bot-api-sec... |
| CVE-2026-32979 | MEDIUM | 6.7 | 0.1% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local cod... |
| CVE-2026-32978 | HIGH | 7.5 | 0.2% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable f... |
| CVE-2026-32975 | CRITICAL | 9.8 | 0.3% | Mar 29, 2026 | OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable gr... |
| CVE-2026-32974 | CRITICAL | 9.8 | 0.2% | Mar 29, 2026 | OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationT... |
| CVE-2026-32973 | CRITICAL | 9.8 | 0.4% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly n... |
| CVE-2026-32972 | HIGH | 7.1 | 0.3% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only oper... |
| CVE-2026-32924 | CRITICAL | 9.8 | 0.3% | Mar 29, 2026 | OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_... |
| CVE-2026-32923 | MEDIUM | 5.4 | 0.2% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild reaction ingestion that fails ... |
| CVE-2026-32922 | CRITICAL | 9.9 | 0.5% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with ... |
| CVE-2026-32919 | MEDIUM | 6.9 | 0.1% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-on... |
| CVE-2026-32918 | CRITICAL | 9.2 | 0.1% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandbox... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now