2026 CVE Vulnerabilities
68,165 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22181 | HIGH | 7.6 | 0.2% | Mar 18, 2026 | OpenClaw versions prior to 2026.3.2 contain a DNS pinning bypass vulnerability in strict URL fetch paths that allows att... |
| CVE-2026-22180 | MEDIUM | 5.3 | 0.1% | Mar 18, 2026 | OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling that allo... |
| CVE-2026-22179 | HIGH | 7.5 | 0.6% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows... |
| CVE-2026-22178 | HIGH | 8.2 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the str... |
| CVE-2026-22177 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars... |
| CVE-2026-22175 | HIGH | 7.1 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always ... |
| CVE-2026-22174 | MEDIUM | 6.8 | 0.1% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback ... |
| CVE-2026-22171 | CRITICAL | 9.1 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untr... |
| CVE-2026-22170 | MEDIUM | 6.5 | 0.3% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability... |
| CVE-2026-22169 | HIGH | 7.1 | 0.2% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows... |
| CVE-2026-22168 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows auth... |
| CVE-2026-29057 | MEDIUM | 6.5 | 0.4% | Mar 18, 2026 | Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 1... |
| CVE-2026-28674 | HIGH | 7.2 | 0.3% | Mar 18, 2026 | xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin... |
| CVE-2026-28673 | HIGH | 7.2 | 0.6% | Mar 18, 2026 | xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin... |
| CVE-2026-27980 | HIGH | 7.5 | 0.7% | Mar 18, 2026 | Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 1... |
| CVE-2026-27979 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1... |
| CVE-2026-4355 | LOW | 3.5 | 0.2% | Mar 18, 2026 | A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_... |
| CVE-2026-4354 | LOW | 3.5 | 0.2% | Mar 18, 2026 | A vulnerability was identified in TRENDnet TEW-824DRU 1.010B01/1.04B01. The impacted element is the function sub_420A78 ... |
| CVE-2026-27978 | MEDIUM | 4.3 | 0.2% | Mar 18, 2026 | Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1... |
| CVE-2026-27977 | MEDIUM | 5.4 | 0.2% | Mar 18, 2026 | Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1... |
| CVE-2026-27895 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d... |
| CVE-2026-27894 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d... |
| CVE-2026-27811 | HIGH | 8.8 | 2.0% | Mar 18, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a comma... |
| CVE-2026-27459 | CRITICAL | 9.8 | 0.7% | Mar 18, 2026 | pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a u... |
| CVE-2026-27448 | MEDIUM | 5.3 | 0.2% | Mar 18, 2026 | pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a u... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now