2026 CVE Vulnerabilities

50,630 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-35633MEDIUM6.9OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that...
CVE-2026-35628MEDIUM6.5OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows ...
CVE-2026-35626MEDIUM6.9OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling t...
CVE-2026-35624MEDIUM5.4OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room na...
CVE-2026-35623MEDIUM6.5OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers...
CVE-2026-35617MEDIUM5.4OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that re...
CVE-2026-33787MEDIUM6.8An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Junipe...
CVE-2026-33786MEDIUM6.8An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Junipe...
CVE-2026-33776MEDIUM6.8A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user w...
CVE-2026-33774MEDIUM5.3An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper N...
CVE-2026-33773MEDIUM6.9An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS...
CVE-2026-21904MEDIUM6.1An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2026-40107MEDIUM6.5SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loos...
CVE-2026-35206MEDIUM4.4Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart wi...
CVE-2026-40087MEDIUM5.3LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-str...
CVE-2026-39977MEDIUM6.3flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key take...
CVE-2026-34500MEDIUM6.5CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Ap...
CVE-2026-32990MEDIUM5.3Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects...
CVE-2026-25854MEDIUM6.1Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDraini...
CVE-2026-35195MEDIUM5.4Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transco...
CVE-2026-34988MEDIUM6.3Wasmtime is a runtime for WebAssembly. From 28.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of it...
CVE-2026-34983MEDIUM5Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free...
CVE-2026-34945MEDIUM6.5Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler conta...
CVE-2026-34944MEDIUM5.7Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, On x86-64 platforms with SSE3 disabl...
CVE-2026-34942MEDIUM6.5Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transco...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now