2026 CVE Vulnerabilities

67,685 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31990HIGH7.1OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to valid...
CVE-2026-31989MEDIUM6.3OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation redirect ...
CVE-2026-29608MEDIUM6.7OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewriting ch...
CVE-2026-29607HIGH7.1OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persistence t...
CVE-2026-28461HIGH8.7OpenClaw versions prior to 2026.3.1 contain an unbounded memory growth vulnerability in the Zalo webhook endpoint that a...
CVE-2026-28460HIGH7.1OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers to ex...
CVE-2026-28449MEDIUM6.5OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed ...
CVE-2026-27670MEDIUM5.8OpenClaw versions prior to 2026.3.2 contain a race condition vulnerability in ZIP extraction that allows local attackers...
CVE-2026-27566HIGH8.8OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fails to...
CVE-2026-22176HIGH7.8OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script generati...
CVE-2026-32743MEDIUM6.5PX4 is an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable to ...
CVE-2026-32255HIGH8.6Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has n...
CVE-2026-3181——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-32805HIGH7.5Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for function...
CVE-2026-32737CRITICAL10Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for function...
CVE-2026-32736MEDIUM4.3The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. An Insecure Direct Object...
CVE-2026-32735LOW2.3openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting i...
CVE-2026-32731CRITICAL9.9ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, ...
CVE-2026-32730HIGH8.1ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication m...
CVE-2026-4407LOW2.1Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color space...
CVE-2026-33163MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-33042MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32944HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32943LOW3.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32886HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now