2026 CVE Vulnerabilities
67,083 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32974 | CRITICAL | 9.8 | 0.2% | Mar 29, 2026 | OpenClaw before 2026.3.12 contains an authentication bypass vulnerability in Feishu webhook mode when only verificationT... |
| CVE-2026-32973 | CRITICAL | 9.8 | 0.4% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an exec allowlist bypass vulnerability where matchesExecAllowlistPattern improperly n... |
| CVE-2026-32972 | HIGH | 7.1 | 0.3% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only oper... |
| CVE-2026-32924 | CRITICAL | 9.8 | 0.3% | Mar 29, 2026 | OpenClaw before 2026.3.12 contains an authorization bypass vulnerability where Feishu reaction events with omitted chat_... |
| CVE-2026-32923 | MEDIUM | 5.4 | 0.2% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild reaction ingestion that fails ... |
| CVE-2026-32922 | CRITICAL | 9.9 | 0.5% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with ... |
| CVE-2026-32919 | MEDIUM | 6.9 | 0.1% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-on... |
| CVE-2026-32918 | CRITICAL | 9.2 | 0.1% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains a session sandbox escape vulnerability in the session_status tool that allows sandbox... |
| CVE-2026-32915 | CRITICAL | 9.3 | 0.1% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagents to access the subagen... |
| CVE-2026-32914 | HIGH | 8.8 | 0.3% | Mar 29, 2026 | OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handle... |
| CVE-2026-23400 | MEDIUM | 5.5 | 0.1% | Mar 29, 2026 | In the Linux kernel, the following vulnerability has been resolved: rust_binder: call set_notification_done() without p... |
| CVE-2026-5043 | HIGH | 8.8 | 0.8% | Mar 29, 2026 | A weakness has been identified in Belkin F9K1122 1.00.33. The impacted element is the function formSetPassword of the fi... |
| CVE-2026-5042 | HIGH | 8.8 | 0.7% | Mar 29, 2026 | A security flaw has been discovered in Belkin F9K1122 1.00.33. The affected element is the function formCrossBandSwitch ... |
| CVE-2026-5041 | MEDIUM | 4.7 | 1.9% | Mar 29, 2026 | A vulnerability was identified in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is the fu... |
| CVE-2026-5037 | LOW | 3.3 | 0.1% | Mar 29, 2026 | A vulnerability was determined in mxml up to 4.0.4. This issue affects the function index_sort of the file mxml-index.c ... |
| CVE-2026-5036 | HIGH | 8.8 | 0.6% | Mar 29, 2026 | A vulnerability was found in Tenda 4G06 04.06.01.29. This vulnerability affects the function fromDhcpListClient of the f... |
| CVE-2026-5035 | CRITICAL | 9.8 | 0.4% | Mar 29, 2026 | A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_wo... |
| CVE-2026-5034 | CRITICAL | 9.8 | 0.3% | Mar 29, 2026 | A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of th... |
| CVE-2026-5033 | CRITICAL | 9.8 | 0.3% | Mar 29, 2026 | A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functi... |
| CVE-2026-5031 | MEDIUM | 4.3 | 0.2% | Mar 29, 2026 | A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_... |
| CVE-2026-5030 | CRITICAL | 9.8 | 2.3% | Mar 29, 2026 | A vulnerability has been found in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function NTPSyncWithHos... |
| CVE-2026-5024 | HIGH | 8.8 | 0.8% | Mar 29, 2026 | A vulnerability was found in D-Link DIR-513 1.10. This issue affects the function formSetEmail of the file /goform/formS... |
| CVE-2026-5023 | MEDIUM | 5.3 | 0.6% | Mar 29, 2026 | A vulnerability has been found in DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6. This vulner... |
| CVE-2026-5021 | HIGH | 8.8 | 0.6% | Mar 29, 2026 | A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromPPTPUserSetting of the file /goform/PPTPUserS... |
| CVE-2026-2602 | MEDIUM | 6.4 | 0.2% | Mar 29, 2026 | The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now