2026 CVE Vulnerabilities
49,191 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41388 | MEDIUM | 6.5 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array s... |
| CVE-2026-41382 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers ... |
| CVE-2026-41381 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attac... |
| CVE-2026-41377 | MEDIUM | 5.1 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failure... |
| CVE-2026-41376 | MEDIUM | 6.5 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an allowlist bypass vulnerability in Matrix thread root and reply context handling th... |
| CVE-2026-41374 | MEDIUM | 6.9 | 0.5% | Apr 28, 2026 | OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowin... |
| CVE-2026-41373 | MEDIUM | 6.1 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary en... |
| CVE-2026-24231 | MEDIUM | 6.3 | 0.1% | Apr 28, 2026 | NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could... |
| CVE-2026-24204 | MEDIUM | 6.5 | 0.4% | Apr 28, 2026 | NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A... |
| CVE-2026-38948 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The... |
| CVE-2026-7283 | MEDIUM | 4.7 | 0.3% | Apr 28, 2026 | A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function... |
| CVE-2026-7282 | MEDIUM | 4.7 | 0.2% | Apr 28, 2026 | A vulnerability was identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function dele... |
| CVE-2026-40969 | MEDIUM | 5.3 | 0.2% | Apr 28, 2026 | The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRP... |
| CVE-2026-6706 | MEDIUM | 6.5 | 0.2% | Apr 28, 2026 | Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to r... |
| CVE-2026-40552 | MEDIUM | 4.7 | 0.3% | Apr 28, 2026 | mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the application and direct access... |
| CVE-2026-40550 | MEDIUM | 6.9 | 0.1% | Apr 28, 2026 | mpGabinet is vulnerable to Privilege Escalation due to excessive database privileges assigned to the user used by the ap... |
| CVE-2026-7309 | MEDIUM | 4.3 | 0.2% | Apr 28, 2026 | A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitra... |
| CVE-2026-7271 | MEDIUM | 5.5 | 0.5% | Apr 28, 2026 | A vulnerability was detected in DV0x creative-ad-agent up to 751b9e5146604dc65049bd0f62dcbdad6212f8a3. Impacted is an un... |
| CVE-2026-7268 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This impacts the function save_category o... |
| CVE-2026-7267 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects an unknown function of the file /view... |
| CVE-2026-7266 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function save_o... |
| CVE-2026-7265 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the f... |
| CVE-2026-7264 | MEDIUM | 6.3 | 0.3% | Apr 28, 2026 | A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function get_cart_items o... |
| CVE-2026-41607 | MEDIUM | 6.5 | 0.9% | Apr 28, 2026 | Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommen... |
| CVE-2026-41606 | MEDIUM | 5.3 | 1.1% | Apr 28, 2026 | Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are reco... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now