2026 CVE Vulnerabilities
49,109 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7306 | MEDIUM | 5.6 | 0.3% | Apr 28, 2026 | A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function o... |
| CVE-2026-7305 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the fi... |
| CVE-2026-37750 | MEDIUM | 6.1 | 0.4% | Apr 28, 2026 | A reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1 allows unauthenticated re... |
| CVE-2026-33467 | MEDIUM | 5.9 | 0.1% | Apr 28, 2026 | Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positione... |
| CVE-2026-7293 | MEDIUM | 4.7 | 0.2% | Apr 28, 2026 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function delete_category of... |
| CVE-2026-7292 | MEDIUM | 5.6 | 0.3% | Apr 28, 2026 | A security vulnerability has been detected in o2oa up to 10.0. This impacts the function syncFile of the file NodeAgent.... |
| CVE-2026-7291 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A weakness has been identified in o2oa up to 10.0. This affects the function FileAction of the file FileAction.java of t... |
| CVE-2026-7290 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A vulnerability was determined in JeecgBoot up to 3.9.1. Impacted is the function SqlInjectionUtil of the file jeecg-boo... |
| CVE-2026-6807 | MEDIUM | 5.5 | 0.2% | Apr 28, 2026 | A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may ... |
| CVE-2026-6238 | MEDIUM | 6.5 | 0.3% | Apr 28, 2026 | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail t... |
| CVE-2026-5794 | MEDIUM | 4.9 | 0.3% | Apr 28, 2026 | A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by tri... |
| CVE-2026-42430 | MEDIUM | 6.5 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in Playwright redirect handling that allow... |
| CVE-2026-42427 | MEDIUM | 5.8 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a remote code execution vulnerability caused by missing environment variable denylist ... |
| CVE-2026-42424 | MEDIUM | 5 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channe... |
| CVE-2026-42421 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared ga... |
| CVE-2026-42420 | MEDIUM | 6.5 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains improper input validation in base64 decode paths that allocate memory before enforcing... |
| CVE-2026-41916 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure become... |
| CVE-2026-41915 | MEDIUM | 6.1 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.4.8 fails to remove git plumbing environment variables from the execution environment before host e... |
| CVE-2026-41913 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.4 contains a race condition vulnerability in shared-secret authentication that allows concurrent ... |
| CVE-2026-41911 | MEDIUM | 6.5 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local f... |
| CVE-2026-41910 | MEDIUM | 4.3 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.8 omits owner-only enforcement for cross-channel allowlist writes in the /allowlist endpoint. An ... |
| CVE-2026-41408 | MEDIUM | 6.5 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limi... |
| CVE-2026-41407 | MEDIUM | 5.3 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.4.2 contains a timing side channel vulnerability in shared-secret comparison call sites that use ea... |
| CVE-2026-41406 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restri... |
| CVE-2026-41403 | MEDIUM | 4 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 misclassifies proxied remote requests as loopback connections in the diffs viewer when allowRe... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now