2026 CVE Vulnerabilities

48,674 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-44117MEDIUM6.3OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips U...
CVE-2026-44111MEDIUM4.3OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the QMD backend memory_get function that allo...
CVE-2026-43583MEDIUM6.5OpenClaw versions 2026.4.10 before 2026.4.14 fail to persist session context during delivery queue recovery for media re...
CVE-2026-43582MEDIUM6.3OpenClaw before 2026.4.10 contains a server-side request forgery vulnerability in browser navigation policy that allows ...
CVE-2026-43579MEDIUM6.5OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that...
CVE-2026-8031MEDIUM5.5A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown func...
CVE-2026-8021MEDIUM4.2Script injection in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage ...
CVE-2026-8020MEDIUM5.3Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromise...
CVE-2026-8019MEDIUM5.4Insufficient policy enforcement in WebApp in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform U...
CVE-2026-8015MEDIUM5.4Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI sp...
CVE-2026-8014MEDIUM4.3Inappropriate implementation in Preload in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-...
CVE-2026-8013MEDIUM4.3Insufficient validation of untrusted input in FedCM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to...
CVE-2026-8012MEDIUM5.4Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromi...
CVE-2026-8011MEDIUM4.3Insufficient policy enforcement in Search in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cros...
CVE-2026-8010MEDIUM6.3Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote att...
CVE-2026-8009MEDIUM5Inappropriate implementation in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromis...
CVE-2026-8008MEDIUM5.4Inappropriate implementation in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a use...
CVE-2026-8006MEDIUM5.4Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a ...
CVE-2026-8005MEDIUM4.3Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the lo...
CVE-2026-8004MEDIUM4.3Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a ...
CVE-2026-8003MEDIUM5.4Insufficient validation of untrusted input in TabGroups in Google Chrome prior to 148.0.7778.96 allowed a remote attacke...
CVE-2026-7999MEDIUM4.3Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potential...
CVE-2026-7998MEDIUM5.4Insufficient validation of untrusted input in Dialog in Google Chrome prior to 148.0.7778.96 allowed a remote attacker w...
CVE-2026-7996MEDIUM4.2Insufficient validation of untrusted input in SSL in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who ...
CVE-2026-7993MEDIUM4.2Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 148.0.7778.96 allowed a remo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now