2026 CVE Vulnerabilities

68,165 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-22181HIGH7.6OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allows att...
CVE-2026-22180MEDIUM5.3OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling that allo...
CVE-2026-22179HIGH7.5OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows...
CVE-2026-22178HIGH8.2OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the str...
CVE-2026-22177HIGH8.8OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars...
CVE-2026-22175HIGH7.1OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always ...
CVE-2026-22174MEDIUM6.8OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback ...
CVE-2026-22171CRITICAL9.1OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untr...
CVE-2026-22170MEDIUM6.5OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability...
CVE-2026-22169HIGH7.1OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows...
CVE-2026-22168HIGH8.8OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows auth...
CVE-2026-29057MEDIUM6.5Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 1...
CVE-2026-28674HIGH7.2xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin...
CVE-2026-28673HIGH7.2xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin...
CVE-2026-27980HIGH7.5Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 1...
CVE-2026-27979HIGH7.5Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1...
CVE-2026-4355LOW3.5A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_...
CVE-2026-4354LOW3.5A vulnerability was identified in TRENDnet TEW-824DRU 1.010B01/1.04B01. The impacted element is the function sub_420A78 ...
CVE-2026-27978MEDIUM4.3Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1...
CVE-2026-27977MEDIUM5.4Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1...
CVE-2026-27895HIGH8.8LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d...
CVE-2026-27894HIGH8.8LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d...
CVE-2026-27811HIGH8.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a comma...
CVE-2026-27459CRITICAL9.8pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a u...
CVE-2026-27448MEDIUM5.3pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a u...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now