2026 CVE Vulnerabilities
50,629 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5448 | MEDIUM | 4.3 | 0.1% | Apr 10, 2026 | X.509 date buffer overflow in wolfSSL_X509_notAfter / wolfSSL_X509_notBefore. A buffer overflow may occur when parsing d... |
| CVE-2026-5392 | MEDIUM | 5.4 | 0.2% | Apr 10, 2026 | Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the heap. The missing bound... |
| CVE-2026-5987 | MEDIUM | 4.7 | 0.2% | Apr 9, 2026 | A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFree... |
| CVE-2026-5986 | MEDIUM | 5.5 | 0.4% | Apr 9, 2026 | A weakness has been identified in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function getTime in the ... |
| CVE-2026-5507 | MEDIUM | 4 | 0.2% | Apr 9, 2026 | When restoring a session from cache, a pointer from the serialized session data is used in a free operation without vali... |
| CVE-2026-5504 | MEDIUM | 5.3 | 0.1% | Apr 9, 2026 | A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover plaintext through repe... |
| CVE-2026-5778 | MEDIUM | 6.5 | 0.2% | Apr 9, 2026 | Integer underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a program crash in the AEAD decryption ... |
| CVE-2026-5772 | MEDIUM | 5.3 | 0.2% | Apr 9, 2026 | A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname... |
| CVE-2026-5263 | MEDIUM | 6.5 | 0.2% | Apr 9, 2026 | URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification ... |
| CVE-2026-40153 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os... |
| CVE-2026-40152 | MEDIUM | 5.3 | 0.3% | Apr 9, 2026 | PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directo... |
| CVE-2026-40151 | MEDIUM | 5.3 | 0.8% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents end... |
| CVE-2026-40150 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_c... |
| CVE-2026-40148 | MEDIUM | 6.5 | 0.2% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the _safe_extractall() function in PraisonAI's recipe registr... |
| CVE-2026-40112 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the Flask API endpoint in src/praisonai/api.py renders agent ... |
| CVE-2026-39848 | MEDIUM | 5.4 | 0.2% | Apr 9, 2026 | Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed ... |
| CVE-2026-35646 | MEDIUM | 6.5 | 0.2% | Apr 9, 2026 | OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that... |
| CVE-2026-35642 | MEDIUM | 5.3 | 0.2% | Apr 9, 2026 | OpenClaw before 2026.3.25 contains an authorization bypass vulnerability where group reaction events bypass the requireM... |
| CVE-2026-35635 | MEDIUM | 6.5 | 0.2% | Apr 9, 2026 | OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that al... |
| CVE-2026-35634 | MEDIUM | 5.1 | 0.1% | Apr 9, 2026 | OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasReq... |
| CVE-2026-35633 | MEDIUM | 6.9 | 0.4% | Apr 9, 2026 | OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that... |
| CVE-2026-35628 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows ... |
| CVE-2026-35626 | MEDIUM | 6.9 | 0.5% | Apr 9, 2026 | OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling t... |
| CVE-2026-35624 | MEDIUM | 5.4 | 0.2% | Apr 9, 2026 | OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room na... |
| CVE-2026-35623 | MEDIUM | 6.5 | 0.4% | Apr 9, 2026 | OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now