2026 CVE Vulnerabilities

67,723 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29056HIGH8.8Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registrat...
CVE-2026-28500CRITICAL9.1Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and inc...
CVE-2026-28499MEDIUM6.1LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correct...
CVE-2026-27545MEDIUM4.7OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attack...
CVE-2026-27524MEDIUM4.3OpenClaw versions prior to 2026.2.21 accept prototype-reserved keys in runtime /debug set override object values, allowi...
CVE-2026-27523HIGH7.5OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowe...
CVE-2026-27522MEDIUM5.5OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon ...
CVE-2026-22217MEDIUM6.1OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allow...
CVE-2026-22181HIGH7.6OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allows att...
CVE-2026-22180MEDIUM5.3OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling that allo...
CVE-2026-22179HIGH7.5OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows...
CVE-2026-22178HIGH8.2OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the str...
CVE-2026-22177HIGH8.8OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars...
CVE-2026-22175HIGH7.1OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always ...
CVE-2026-22174MEDIUM6.8OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback ...
CVE-2026-22171CRITICAL9.1OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untr...
CVE-2026-22170MEDIUM6.5OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability...
CVE-2026-22169HIGH7.1OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows...
CVE-2026-22168HIGH8.8OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows auth...
CVE-2026-29057MEDIUM6.5Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 1...
CVE-2026-28674HIGH7.2xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin...
CVE-2026-28673HIGH7.2xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin...
CVE-2026-27980HIGH7.5Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 1...
CVE-2026-27979HIGH7.5Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1...
CVE-2026-4355LOW3.5A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now