2026 CVE Vulnerabilities
67,723 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-29056 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | Kanboard is project management software focused on Kanban methodology. Prior to 1.2.51, Kanboard's user invite registrat... |
| CVE-2026-28500 | CRITICAL | 9.1 | 0.3% | Mar 18, 2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and inc... |
| CVE-2026-28499 | MEDIUM | 6.1 | 0.3% | Mar 18, 2026 | LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correct... |
| CVE-2026-27545 | MEDIUM | 4.7 | 0.1% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attack... |
| CVE-2026-27524 | MEDIUM | 4.3 | 0.2% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.21 accept prototype-reserved keys in runtime /debug set override object values, allowi... |
| CVE-2026-27523 | HIGH | 7.5 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowe... |
| CVE-2026-27522 | MEDIUM | 5.5 | 0.4% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon ... |
| CVE-2026-22217 | MEDIUM | 6.1 | 0.1% | Mar 18, 2026 | OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allow... |
| CVE-2026-22181 | HIGH | 7.6 | 0.2% | Mar 18, 2026 | OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allows att... |
| CVE-2026-22180 | MEDIUM | 5.3 | 0.1% | Mar 18, 2026 | OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling that allo... |
| CVE-2026-22179 | HIGH | 7.5 | 0.6% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows... |
| CVE-2026-22178 | HIGH | 8.2 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the str... |
| CVE-2026-22177 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars... |
| CVE-2026-22175 | HIGH | 7.1 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always ... |
| CVE-2026-22174 | MEDIUM | 6.8 | 0.1% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback ... |
| CVE-2026-22171 | CRITICAL | 9.1 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untr... |
| CVE-2026-22170 | MEDIUM | 6.5 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability... |
| CVE-2026-22169 | HIGH | 7.1 | 0.2% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows... |
| CVE-2026-22168 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows auth... |
| CVE-2026-29057 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 1... |
| CVE-2026-28674 | HIGH | 7.2 | 0.3% | Mar 18, 2026 | xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin... |
| CVE-2026-28673 | HIGH | 7.2 | 0.6% | Mar 18, 2026 | xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin... |
| CVE-2026-27980 | HIGH | 7.5 | 0.7% | Mar 18, 2026 | Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 1... |
| CVE-2026-27979 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1... |
| CVE-2026-4355 | LOW | 3.5 | 0.2% | Mar 18, 2026 | A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now