2026 CVE Vulnerabilities

68,738 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-22179HIGH7.5OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows...
CVE-2026-22178HIGH8.2OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the str...
CVE-2026-22177HIGH8.8OpenClaw versions prior to 2026.2.21 fail to filter dangerous process-control environment variables from config env.vars...
CVE-2026-22175HIGH7.1OpenClaw versions prior to 2026.2.23 contain an exec approval bypass vulnerability in allowlist mode where allow-always ...
CVE-2026-22174MEDIUM6.8OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback ...
CVE-2026-22171CRITICAL9.1OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untr...
CVE-2026-22170MEDIUM6.5OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability...
CVE-2026-22169HIGH7.1OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows...
CVE-2026-22168HIGH8.8OpenClaw versions prior to 2026.2.21 contain an approval-integrity mismatch vulnerability in system.run that allows auth...
CVE-2026-29057MEDIUM6.5Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 1...
CVE-2026-28674HIGH7.2xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin...
CVE-2026-28673HIGH7.2xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin...
CVE-2026-27980HIGH7.5Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 1...
CVE-2026-27979HIGH7.5Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1...
CVE-2026-4355LOW3.5A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_...
CVE-2026-4354LOW3.5A vulnerability was identified in TRENDnet TEW-824DRU 1.010B01/1.04B01. The impacted element is the function sub_420A78 ...
CVE-2026-27978MEDIUM4.3Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1...
CVE-2026-27977MEDIUM5.4Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 1...
CVE-2026-27895HIGH8.8LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d...
CVE-2026-27894HIGH8.8LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP d...
CVE-2026-27811HIGH8.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a comma...
CVE-2026-27459CRITICAL9.8pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a u...
CVE-2026-27448MEDIUM5.3pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a u...
CVE-2026-26004MEDIUM6.5Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organi...
CVE-2026-26001HIGH8.8The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now