2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41340 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains an authentication boundary vulnerability where Telegram legacy allowFrom migration in... |
| CVE-2026-41339 | MEDIUM | 5.3 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.4.2 exposes configPath and stateDir metadata in Gateway connect success snapshots to non-admin auth... |
| CVE-2026-41338 | MEDIUM | 5 | 0.1% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a time-of-check-time-of-use vulnerability in sandbox file operations that allows atta... |
| CVE-2026-41337 | MEDIUM | 6.3 | 0.2% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a callback origin mutation vulnerability in Plivo voice-call replay that allows attac... |
| CVE-2026-41335 | MEDIUM | 6.9 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains an information disclosure vulnerability in the Control Interface bootstrap JSON that ... |
| CVE-2026-41333 | MEDIUM | 6.3 | 0.4% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumv... |
| CVE-2026-41332 | MEDIUM | 5.8 | 0.1% | Apr 23, 2026 | OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CON... |
| CVE-2026-2708 | MEDIUM | 5.3 | 0.3% | Apr 23, 2026 | A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_commo... |
| CVE-2026-41241 | MEDIUM | 5.4 | 0.2% | Apr 23, 2026 | pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submissio... |
| CVE-2026-41213 | MEDIUM | 5.9 | 0.3% | Apr 23, 2026 | @node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7... |
| CVE-2026-41173 | MEDIUM | 5.9 | 0.3% | Apr 23, 2026 | The AWS X-Ray Remote Sampler package provides a sampler which can get sampling configurations from AWS X-Ray. Prior to 0... |
| CVE-2026-41078 | MEDIUM | 5.9 | 0.2% | Apr 23, 2026 | OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier, OpenTelemetry.Exporter.Jaeger may allow... |
| CVE-2026-40894 | MEDIUM | 5.3 | 0.5% | Apr 23, 2026 | OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Exte... |
| CVE-2026-31173 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31169 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31168 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31167 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31166 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31163 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31162 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-41909 | MEDIUM | 5.4 | 0.2% | Apr 23, 2026 | OpenClaw before 2026.4.20 contains an improper authorization vulnerability in paired-device pairing management that allo... |
| CVE-2026-41908 | MEDIUM | 6.5 | 0.2% | Apr 23, 2026 | OpenClaw before 2026.4.20 contains a scope enforcement bypass vulnerability in the assistant-media route that allows tru... |
| CVE-2026-40891 | MEDIUM | 5.3 | 0.2% | Apr 23, 2026 | OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry over gRPC u... |
| CVE-2026-40182 | MEDIUM | 5.9 | 0.3% | Apr 23, 2026 | OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry to a back-e... |
| CVE-2026-31179 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now