2026 CVE Vulnerabilities

50,629 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-5448MEDIUM4.3X.509 date buffer overflow in wolfSSL_X509_notAfter / wolfSSL_X509_notBefore. A buffer overflow may occur when parsing d...
CVE-2026-5392MEDIUM5.4Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the heap. The missing bound...
CVE-2026-5987MEDIUM4.7A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFree...
CVE-2026-5986MEDIUM5.5A weakness has been identified in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function getTime in the ...
CVE-2026-5507MEDIUM4When restoring a session from cache, a pointer from the serialized session data is used in a free operation without vali...
CVE-2026-5504MEDIUM5.3A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover plaintext through repe...
CVE-2026-5778MEDIUM6.5Integer underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a program crash in the AEAD decryption ...
CVE-2026-5772MEDIUM5.3A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname...
CVE-2026-5263MEDIUM6.5URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification ...
CVE-2026-40153MEDIUM6.5PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os...
CVE-2026-40152MEDIUM5.3PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directo...
CVE-2026-40151MEDIUM5.3PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents end...
CVE-2026-40150MEDIUM6.5PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_c...
CVE-2026-40148MEDIUM6.5PraisonAI is a multi-agent teams system. Prior to 4.5.128, the _safe_extractall() function in PraisonAI's recipe registr...
CVE-2026-40112MEDIUM6.1PraisonAI is a multi-agent teams system. Prior to 4.5.128, the Flask API endpoint in src/praisonai/api.py renders agent ...
CVE-2026-39848MEDIUM5.4Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed ...
CVE-2026-35646MEDIUM6.5OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that...
CVE-2026-35642MEDIUM5.3OpenClaw before 2026.3.25 contains an authorization bypass vulnerability where group reaction events bypass the requireM...
CVE-2026-35635MEDIUM6.5OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that al...
CVE-2026-35634MEDIUM5.1OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasReq...
CVE-2026-35633MEDIUM6.9OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that...
CVE-2026-35628MEDIUM6.5OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows ...
CVE-2026-35626MEDIUM6.9OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling t...
CVE-2026-35624MEDIUM5.4OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room na...
CVE-2026-35623MEDIUM6.5OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now