2026 CVE Vulnerabilities

48,542 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-54228HIGH7.8A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Betwee...
CVE-2026-6676HIGH7.8Heap buffer out-of-bounds write vulnerability in Avira Antivirus engine when scanning a malformed POSIX tar archive may ...
CVE-2026-12068HIGH7.4Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacke...
CVE-2026-53868HIGH8.7Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary...
CVE-2026-53836HIGH8.8OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows ...
CVE-2026-53832HIGH7.1OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge...
CVE-2026-53831HIGH8.1OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that a...
CVE-2026-53829HIGH8.5OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide com...
CVE-2026-53828HIGH8.8OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authentic...
CVE-2026-53825HIGH7.1OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows aut...
CVE-2026-53823HIGH8.6OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Sl...
CVE-2026-53822HIGH8.8OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between appro...
CVE-2026-53821HIGH8.8OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or...
CVE-2026-53608HIGH8.7ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostroph...
CVE-2026-49396HIGH7.1Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to be...
CVE-2026-48119HIGH7.1Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to b...
CVE-2026-47120HIGH7.1Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be...
CVE-2026-46717HIGH7.7Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be...
CVE-2026-41158HIGH7.8Software installed and run as a non-privileged user may conduct GPU system calls to write to arbitrary freed physical pa...
CVE-2026-34195HIGH8.8Software installed and run as a non-privileged user may conduct intentional GPU sparse memory API calls to cause out of ...
CVE-2026-54057HIGH7.8Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply re...
CVE-2026-54056HIGH7.1Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote d...
CVE-2026-4870HIGH7.5IBM Qiskit SDK 0.43.0 through 2.5.0 could allow an attacker to trigger a segmentation fault leading to a denial of servi...
CVE-2026-45013HIGH8.1ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password r...
CVE-2026-45012HIGH7.6ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authen...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now