2026 CVE Vulnerabilities

65,537 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100534LOW3.1OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that al...
CVE-2026-100533MEDIUM5.3OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Uni...
CVE-2026-100532HIGH8.1@openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without p...
CVE-2026-100531MEDIUM6.5The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when ...
CVE-2026-100530HIGH7.3OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved c...
CVE-2026-100529MEDIUM6.4OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always ap...
CVE-2026-100528MEDIUM5.4OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In ...
CVE-2026-100527MEDIUM5.3OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthent...
CVE-2026-100526MEDIUM5.3OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped medi...
CVE-2026-100525MEDIUM4.3The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce t...
CVE-2026-100524MEDIUM5.4Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attacker...
CVE-2026-100523MEDIUM6.1Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter ...
CVE-2026-100522MEDIUM6.1Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is ...
CVE-2026-100521MEDIUM6.1Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter t...
CVE-2026-100520HIGH8.8Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that...
CVE-2026-100505MEDIUM4.4Ghidra versions 9.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when d...
CVE-2026-100504HIGH7Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 ...
CVE-2026-100503LOW3.3Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter f...
CVE-2026-96795HIGH8.8Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py acc...
CVE-2026-86066MEDIUM5.9Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-a...
CVE-2026-57449HIGH7.1Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authe...
CVE-2026-9655——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9652——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-92842MEDIUM5.9The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a l...
CVE-2026-91768MEDIUM6.5The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now