2026 CVE Vulnerabilities

48,557 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-4893MEDIUM5.3An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS pac...
CVE-2026-4891MEDIUM5.3A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a den...
CVE-2026-45005MEDIUM6OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to re...
CVE-2026-45003MEDIUM5OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC...
CVE-2026-45002MEDIUM6.3OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks...
CVE-2026-45000MEDIUM5OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skip...
CVE-2026-44999MEDIUM6.3OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webho...
CVE-2026-44998MEDIUM5.4OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and LSP tools to circumvent c...
CVE-2026-44997MEDIUM4.3OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to ...
CVE-2026-44996MEDIUM6.3OpenClaw before 2026.4.15 contains an arbitrary local file read vulnerability in the webchat audio embedding helper that...
CVE-2026-44994MEDIUM6.3OpenClaw before 2026.4.22 contains an authentication bypass vulnerability in the Control UI bootstrap config endpoint th...
CVE-2026-44993MEDIUM5.4OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassi...
CVE-2026-44992MEDIUM5OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace d...
CVE-2026-44991MEDIUM4.2OpenClaw before 2026.4.21 contains an authorization bypass vulnerability in command-auth.ts that allows non-owner sender...
CVE-2026-44777MEDIUM5.5jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detectio...
CVE-2026-44659MEDIUM4.7Zen is a firefox-based browser. Prior to 1.19.12b, the ZEN Browser incorrectly truncates long hostnames in the address b...
CVE-2026-44226MEDIUM5.3pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns fu...
CVE-2026-43896MEDIUM5.5jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a c...
CVE-2026-43895MEDIUM4.4jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-langu...
CVE-2026-43894MEDIUM5.5jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX...
CVE-2026-43638MEDIUM5.4Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to...
CVE-2026-42865MEDIUM4.3Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis...
CVE-2026-42857MEDIUM5.4Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_ht...
CVE-2026-42316MEDIUM6.5kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2...
CVE-2026-42315MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now