2026 CVE Vulnerabilities

67,083 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32974CRITICAL9.8OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationT...
CVE-2026-32973CRITICAL9.8OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly n...
CVE-2026-32972HIGH7.1OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only oper...
CVE-2026-32924CRITICAL9.8OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_...
CVE-2026-32923MEDIUM5.4OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild reaction ingestion that fails ...
CVE-2026-32922CRITICAL9.9OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with ...
CVE-2026-32919MEDIUM6.9OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-on...
CVE-2026-32918CRITICAL9.2OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandbox...
CVE-2026-32915CRITICAL9.3OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagen...
CVE-2026-32914HIGH8.8OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handle...
CVE-2026-23400MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: rust_binder: call set_notification_done() without p...
CVE-2026-5043HIGH8.8A weakness has been identified in Belkin F9K1122 1.00.33. The impacted element is the function formSetPassword of the fi...
CVE-2026-5042HIGH8.8A security flaw has been discovered in Belkin F9K1122 1.00.33. The affected element is the function formCrossBandSwitch ...
CVE-2026-5041MEDIUM4.7A vulnerability was identified in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is the fu...
CVE-2026-5037LOW3.3A vulnerability was determined in mxml up to 4.0.4. This issue affects the function index_sort of the file mxml-index.c ...
CVE-2026-5036HIGH8.8A vulnerability was found in Tenda 4G06 04.06.01.29. This vulnerability affects the function fromDhcpListClient of the f...
CVE-2026-5035CRITICAL9.8A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_wo...
CVE-2026-5034CRITICAL9.8A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of th...
CVE-2026-5033CRITICAL9.8A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functi...
CVE-2026-5031MEDIUM4.3A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_...
CVE-2026-5030CRITICAL9.8A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHos...
CVE-2026-5024HIGH8.8A vulnerability was found in D-Link DIR-513 1.10. This issue affects the function formSetEmail of the file /goform/formS...
CVE-2026-5023MEDIUM5.3A vulnerability has been found in DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6. This vulner...
CVE-2026-5021HIGH8.8A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromPPTPUserSetting of the file /goform/PPTPUserS...
CVE-2026-2602MEDIUM6.4The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now