2026 CVE Vulnerabilities

67,075 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4946HIGH8.8Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automatically extracted binary data...
CVE-2026-0562HIGH8.3A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or rej...
CVE-2026-0560HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in th...
CVE-2026-0558CRITICAL9.8A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and proces...
CVE-2026-34005HIGH8.8In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via s...
CVE-2026-5046HIGH8.8A flaw has been found in Tenda FH1201 1.2.0.14(408). Affected is the function formWrlExtraSet of the file /goform/WrlExt...
CVE-2026-5045HIGH8.8A vulnerability was detected in Tenda FH1201 1.2.0.14(408). This impacts the function WrlclientSet of the file /goform/W...
CVE-2026-5044HIGH8.8A security vulnerability has been detected in Belkin F9K1122 1.00.33. This affects the function formSetSystemSettings of...
CVE-2026-33575HIGH8.6OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials directly in pairing setup codes generated by /pai...
CVE-2026-33574MEDIUM4.7OpenClaw before 2026.3.8 contains a path traversal vulnerability in the skills download installer that validates the too...
CVE-2026-33573HIGH8.8OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in the gateway agent RPC that allows authentica...
CVE-2026-33572MEDIUM5.5OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local u...
CVE-2026-32987CRITICAL9.8OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/de...
CVE-2026-32980HIGH8.7OpenClaw before 2026.3.13 reads and buffers Telegram webhook request bodies before validating the x-telegram-bot-api-sec...
CVE-2026-32979MEDIUM6.7OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local cod...
CVE-2026-32978HIGH7.5OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable f...
CVE-2026-32975CRITICAL9.8OpenClaw before 2026.3.12 contains a weak authorization vulnerability in Zalouser allowlist mode that matches mutable gr...
CVE-2026-32974CRITICAL9.8OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationT...
CVE-2026-32973CRITICAL9.8OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly n...
CVE-2026-32972HIGH7.1OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only oper...
CVE-2026-32924CRITICAL9.8OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_...
CVE-2026-32923MEDIUM5.4OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild reaction ingestion that fails ...
CVE-2026-32922CRITICAL9.9OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with ...
CVE-2026-32919MEDIUM6.9OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-on...
CVE-2026-32918CRITICAL9.2OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandbox...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now