2026 CVE Vulnerabilities

68,698 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27096HIGH8.1Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows O...
CVE-2026-1238HIGH7.2The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) para...
CVE-2026-1276MEDIUM5.4IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows a...
CVE-2026-32000HIGH7.1OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution t...
CVE-2026-31999HIGH7.8OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in ...
CVE-2026-31998HIGH8.6OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plu...
CVE-2026-31997MEDIUM6.7OpenClaw versions prior to 2026.3.1 fail to pin executable identity for non-path-like argv[0] tokens in system.run appro...
CVE-2026-31996MEDIUM4.4OpenClaw versions prior to 2026.2.19 tools.exec.safeBins contains an input validation bypass vulnerability that allows a...
CVE-2026-31995HIGH7OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Wind...
CVE-2026-31994HIGH7.8OpenClaw versions prior to 2026.2.19 contain a local command injection vulnerability in Windows scheduled task script ge...
CVE-2026-31993MEDIUM6.4OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion app that...
CVE-2026-31992HIGH8.8OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allows auth...
CVE-2026-31991MEDIUM4.6OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where Signal group allowlist policy i...
CVE-2026-31990HIGH7.1OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to valid...
CVE-2026-31989MEDIUM6.3OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation redirect ...
CVE-2026-29608MEDIUM6.7OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewriting ch...
CVE-2026-29607HIGH7.1OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persistence t...
CVE-2026-28461HIGH8.7OpenClaw versions prior to 2026.3.1 contain an unbounded memory growth vulnerability in the Zalo webhook endpoint that a...
CVE-2026-28460HIGH7.1OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers to ex...
CVE-2026-28449MEDIUM6.5OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed ...
CVE-2026-27670MEDIUM5.8OpenClaw versions prior to 2026.3.2 contain a race condition vulnerability in ZIP extraction that allows local attackers...
CVE-2026-27566HIGH8.8OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fails to...
CVE-2026-22176HIGH7.8OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script generati...
CVE-2026-32743MEDIUM6.5PX4 is an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable to ...
CVE-2026-32255HIGH8.6Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has n...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now