2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-41340MEDIUM6.5OpenClaw before 2026.3.31 contains an authentication boundary vulnerability where Telegram legacy allowFrom migration in...
CVE-2026-41339MEDIUM5.3OpenClaw before 2026.4.2 exposes configPath and stateDir metadata in Gateway connect success snapshots to non-admin auth...
CVE-2026-41338MEDIUM5OpenClaw before 2026.3.31 contains a time-of-check-time-of-use vulnerability in sandbox file operations that allows atta...
CVE-2026-41337MEDIUM6.3OpenClaw before 2026.3.31 contains a callback origin mutation vulnerability in Plivo voice-call replay that allows attac...
CVE-2026-41335MEDIUM6.9OpenClaw before 2026.3.31 contains an information disclosure vulnerability in the Control Interface bootstrap JSON that ...
CVE-2026-41333MEDIUM6.3OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumv...
CVE-2026-41332MEDIUM5.8OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CON...
CVE-2026-2708MEDIUM5.3A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_commo...
CVE-2026-41241MEDIUM5.4pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submissio...
CVE-2026-41213MEDIUM5.9@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7...
CVE-2026-41173MEDIUM5.9The AWS X-Ray Remote Sampler package provides a sampler which can get sampling configurations from AWS X-Ray. Prior to 0...
CVE-2026-41078MEDIUM5.9OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier, OpenTelemetry.Exporter.Jaeger may allow...
CVE-2026-40894MEDIUM5.3OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Exte...
CVE-2026-31173MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31169MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31168MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31167MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31166MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31163MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31162MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-41909MEDIUM5.4OpenClaw before 2026.4.20 contains an improper authorization vulnerability in paired-device pairing management that allo...
CVE-2026-41908MEDIUM6.5OpenClaw before 2026.4.20 contains a scope enforcement bypass vulnerability in the assistant-media route that allows tru...
CVE-2026-40891MEDIUM5.3OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry over gRPC u...
CVE-2026-40182MEDIUM5.9OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry to a back-e...
CVE-2026-31179MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now