2026 CVE Vulnerabilities
45,436 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0141 | MEDIUM | 4.3 | 0.2% | Jun 16, 2026 | In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to ... |
| CVE-2026-0140 | MEDIUM | 4.3 | 0.2% | Jun 16, 2026 | In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote... |
| CVE-2026-0136 | MEDIUM | 6.5 | 0.3% | Jun 16, 2026 | In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of serv... |
| CVE-2026-0128 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead ... |
| CVE-2026-0127 | MEDIUM | 6.5 | 0.3% | Jun 16, 2026 | In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory... |
| CVE-2026-53863 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidate... |
| CVE-2026-53862 | MEDIUM | 5.4 | 0.1% | Jun 16, 2026 | OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to ... |
| CVE-2026-53860 | MEDIUM | 5.4 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match ... |
| CVE-2026-53859 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparison... |
| CVE-2026-53856 | MEDIUM | 5.7 | 0.1% | Jun 16, 2026 | OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores... |
| CVE-2026-53854 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication t... |
| CVE-2026-53852 | MEDIUM | 5.4 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticat... |
| CVE-2026-53851 | MEDIUM | 6.3 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent... |
| CVE-2026-53850 | MEDIUM | 6.8 | 0.1% | Jun 16, 2026 | OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows aut... |
| CVE-2026-53848 | MEDIUM | 4.3 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wr... |
| CVE-2026-53847 | MEDIUM | 5.4 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that allows Gate... |
| CVE-2026-53845 | MEDIUM | 4.3 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected dispatch ... |
| CVE-2026-53844 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows a... |
| CVE-2026-53841 | MEDIUM | 6.1 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe j... |
| CVE-2026-4367 | MEDIUM | 5.5 | 0.1% | Jun 16, 2026 | A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `x... |
| CVE-2026-48775 | MEDIUM | 6.8 | 0.2% | Jun 16, 2026 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ... |
| CVE-2026-47963 | MEDIUM | 5.5 | 0.2% | Jun 16, 2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosur... |
| CVE-2026-47934 | MEDIUM | 5.5 | 0.2% | Jun 16, 2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosur... |
| CVE-2026-47927 | MEDIUM | 5.5 | 0.2% | Jun 16, 2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosur... |
| CVE-2026-47748 | MEDIUM | 5.5 | 0.2% | Jun 16, 2026 | stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Ima... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now