2026 CVE Vulnerabilities
48,542 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54228 | HIGH | 7.8 | 0.1% | Jun 13, 2026 | A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Betwee... |
| CVE-2026-6676 | HIGH | 7.8 | 0.1% | Jun 12, 2026 | Heap buffer out-of-bounds write vulnerability in Avira Antivirus engine when scanning a malformed POSIX tar archive may ... |
| CVE-2026-12068 | HIGH | 7.4 | 0.3% | Jun 12, 2026 | Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacke... |
| CVE-2026-53868 | HIGH | 8.7 | 0.3% | Jun 12, 2026 | Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary... |
| CVE-2026-53836 | HIGH | 8.8 | 0.5% | Jun 12, 2026 | OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows ... |
| CVE-2026-53832 | HIGH | 7.1 | 0.1% | Jun 12, 2026 | OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge... |
| CVE-2026-53831 | HIGH | 8.1 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that a... |
| CVE-2026-53829 | HIGH | 8.5 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide com... |
| CVE-2026-53828 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authentic... |
| CVE-2026-53825 | HIGH | 7.1 | 0.4% | Jun 12, 2026 | OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows aut... |
| CVE-2026-53823 | HIGH | 8.6 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Sl... |
| CVE-2026-53822 | HIGH | 8.8 | 1.0% | Jun 12, 2026 | OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between appro... |
| CVE-2026-53821 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or... |
| CVE-2026-53608 | HIGH | 8.7 | 0.2% | Jun 12, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostroph... |
| CVE-2026-49396 | HIGH | 7.1 | 0.1% | Jun 12, 2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to be... |
| CVE-2026-48119 | HIGH | 7.1 | 0.3% | Jun 12, 2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to b... |
| CVE-2026-47120 | HIGH | 7.1 | 0.3% | Jun 12, 2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be... |
| CVE-2026-46717 | HIGH | 7.7 | 0.3% | Jun 12, 2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be... |
| CVE-2026-41158 | HIGH | 7.8 | 0.1% | Jun 12, 2026 | Software installed and run as a non-privileged user may conduct GPU system calls to write to arbitrary freed physical pa... |
| CVE-2026-34195 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | Software installed and run as a non-privileged user may conduct intentional GPU sparse memory API calls to cause out of ... |
| CVE-2026-54057 | HIGH | 7.8 | 0.2% | Jun 12, 2026 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply re... |
| CVE-2026-54056 | HIGH | 7.1 | 0.3% | Jun 12, 2026 | Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote d... |
| CVE-2026-4870 | HIGH | 7.5 | 0.3% | Jun 12, 2026 | IBM Qiskit SDK 0.43.0 through 2.5.0 could allow an attacker to trigger a segmentation fault leading to a denial of servi... |
| CVE-2026-45013 | HIGH | 8.1 | 0.3% | Jun 12, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 have a password r... |
| CVE-2026-45012 | HIGH | 7.6 | 0.2% | Jun 12, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authen... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now