2026 CVE Vulnerabilities

48,527 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-0150HIGH7.8In ExecuteGraph command handler of EdgeTPU firmware, there is a possible out of bounds write due to an integer overflow....
CVE-2026-0149HIGH8.8In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote...
CVE-2026-0148HIGH8.8In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to an integer overf...
CVE-2026-0147HIGH8.8In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missi...
CVE-2026-0146HIGH8.8In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write due to a missing bou...
CVE-2026-0143HIGH7.8In lwis_device_external_event_emit of lwis_event.c, there is a possible memory corruption due to a use after free. This ...
CVE-2026-0139HIGH8.8In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code executio...
CVE-2026-0138HIGH7.8In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption. This coul...
CVE-2026-0137HIGH7.8In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use afte...
CVE-2026-0135HIGH7.8In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution...
CVE-2026-0133HIGH7.8In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due t...
CVE-2026-0132HIGH8.8In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code executio...
CVE-2026-0131HIGH7.3In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to loca...
CVE-2026-0125HIGH7In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to loc...
CVE-2026-53866HIGH8.1OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authent...
CVE-2026-53865HIGH7.2OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-der...
CVE-2026-53864HIGH8.1OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that all...
CVE-2026-53858HIGH7.1OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY c...
CVE-2026-53857HIGH8.6OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata c...
CVE-2026-53855HIGH8.1OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict ...
CVE-2026-53853HIGH8.3OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to ...
CVE-2026-53849HIGH8.6OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates ...
CVE-2026-53846HIGH7.1OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files...
CVE-2026-53843HIGH8.8OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session...
CVE-2026-53842HIGH7.1OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now