2026 CVE Vulnerabilities

49,191 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-41388MEDIUM6.5OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array s...
CVE-2026-41382MEDIUM5.4OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers ...
CVE-2026-41381MEDIUM5.4OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attac...
CVE-2026-41377MEDIUM5.1OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failure...
CVE-2026-41376MEDIUM6.5OpenClaw before 2026.3.31 contains an allowlist bypass vulnerability in Matrix thread root and reply context handling th...
CVE-2026-41374MEDIUM6.9OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowin...
CVE-2026-41373MEDIUM6.1OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary en...
CVE-2026-24231MEDIUM6.3NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could...
CVE-2026-24204MEDIUM6.5NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A...
CVE-2026-38948MEDIUM5.4Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The...
CVE-2026-7283MEDIUM4.7A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function...
CVE-2026-7282MEDIUM4.7A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function dele...
CVE-2026-40969MEDIUM5.3The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRP...
CVE-2026-6706MEDIUM6.5Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to r...
CVE-2026-40552MEDIUM4.7mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the application and direct access...
CVE-2026-40550MEDIUM6.9mpGabinet is vulnerable to Privilege Escalation due to excessive database privileges assigned to the user used by the ap...
CVE-2026-7309MEDIUM4.3A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitra...
CVE-2026-7271MEDIUM5.5A vulnerability was detected in DV0x creative-ad-agent up to 751b9e5146604dc65049bd0f62dcbdad6212f8a3. Impacted is an un...
CVE-2026-7268MEDIUM6.3A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This impacts the function save_category o...
CVE-2026-7267MEDIUM6.3A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects an unknown function of the file /view...
CVE-2026-7266MEDIUM6.3A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function save_o...
CVE-2026-7265MEDIUM6.3A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the f...
CVE-2026-7264MEDIUM6.3A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function get_cart_items o...
CVE-2026-41607MEDIUM6.5Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommen...
CVE-2026-41606MEDIUM5.3Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are reco...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now