2026 CVE Vulnerabilities
67,685 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31990 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to valid... |
| CVE-2026-31989 | MEDIUM | 6.3 | 0.2% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation redirect ... |
| CVE-2026-29608 | MEDIUM | 6.7 | 0.1% | Mar 19, 2026 | OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewriting ch... |
| CVE-2026-29607 | HIGH | 7.1 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persistence t... |
| CVE-2026-28461 | HIGH | 8.7 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.1 contain an unbounded memory growth vulnerability in the Zalo webhook endpoint that a... |
| CVE-2026-28460 | HIGH | 7.1 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers to ex... |
| CVE-2026-28449 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed ... |
| CVE-2026-27670 | MEDIUM | 5.8 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.2 contain a race condition vulnerability in ZIP extraction that allows local attackers... |
| CVE-2026-27566 | HIGH | 8.8 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fails to... |
| CVE-2026-22176 | HIGH | 7.8 | 0.6% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script generati... |
| CVE-2026-32743 | MEDIUM | 6.5 | 0.4% | Mar 19, 2026 | PX4 is an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable to ... |
| CVE-2026-32255 | HIGH | 8.6 | 10.1% | Mar 19, 2026 | Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has n... |
| CVE-2026-3181 | — | — | — | Mar 18, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-32805 | HIGH | 7.5 | 0.4% | Mar 18, 2026 | Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for function... |
| CVE-2026-32737 | CRITICAL | 10 | 0.4% | Mar 18, 2026 | Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for function... |
| CVE-2026-32736 | MEDIUM | 4.3 | 0.2% | Mar 18, 2026 | The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. An Insecure Direct Object... |
| CVE-2026-32735 | LOW | 2.3 | 0.3% | Mar 18, 2026 | openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting i... |
| CVE-2026-32731 | CRITICAL | 9.9 | 0.4% | Mar 18, 2026 | ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, ... |
| CVE-2026-32730 | HIGH | 8.1 | 0.4% | Mar 18, 2026 | ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication m... |
| CVE-2026-4407 | LOW | 2.1 | 0.1% | Mar 18, 2026 | Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color space... |
| CVE-2026-33163 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-33042 | MEDIUM | 5.3 | 0.3% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32944 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32943 | LOW | 3.1 | 0.2% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32886 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now