2026 CVE Vulnerabilities
50,680 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40112 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the Flask API endpoint in src/praisonai/api.py renders agent ... |
| CVE-2026-39848 | MEDIUM | 5.4 | 0.2% | Apr 9, 2026 | Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed ... |
| CVE-2026-35646 | MEDIUM | 6.5 | 0.2% | Apr 9, 2026 | OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that... |
| CVE-2026-35642 | MEDIUM | 5.3 | 0.2% | Apr 9, 2026 | OpenClaw before 2026.3.25 contains an authorization bypass vulnerability where group reaction events bypass the requireM... |
| CVE-2026-35635 | MEDIUM | 6.5 | 0.2% | Apr 9, 2026 | OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that al... |
| CVE-2026-35634 | MEDIUM | 5.1 | 0.1% | Apr 9, 2026 | OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasReq... |
| CVE-2026-35633 | MEDIUM | 6.9 | 0.4% | Apr 9, 2026 | OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that... |
| CVE-2026-35628 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows ... |
| CVE-2026-35626 | MEDIUM | 6.9 | 0.5% | Apr 9, 2026 | OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling t... |
| CVE-2026-35624 | MEDIUM | 5.4 | 0.2% | Apr 9, 2026 | OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room na... |
| CVE-2026-35623 | MEDIUM | 6.5 | 0.4% | Apr 9, 2026 | OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers... |
| CVE-2026-35617 | MEDIUM | 5.4 | 0.2% | Apr 9, 2026 | OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that re... |
| CVE-2026-33787 | MEDIUM | 6.8 | 0.1% | Apr 9, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Junipe... |
| CVE-2026-33786 | MEDIUM | 6.8 | 0.1% | Apr 9, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Junipe... |
| CVE-2026-33776 | MEDIUM | 6.8 | 0.1% | Apr 9, 2026 | A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS and Junos OS Evolved allows a local user w... |
| CVE-2026-33774 | MEDIUM | 5.3 | 0.2% | Apr 9, 2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper N... |
| CVE-2026-33773 | MEDIUM | 6.9 | 0.2% | Apr 9, 2026 | An Incorrect Initialization of Resource vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS... |
| CVE-2026-21904 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network... |
| CVE-2026-40107 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loos... |
| CVE-2026-35206 | MEDIUM | 4.4 | 0.2% | Apr 9, 2026 | Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart wi... |
| CVE-2026-40087 | MEDIUM | 5.3 | 0.3% | Apr 9, 2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-str... |
| CVE-2026-39977 | MEDIUM | 6.3 | 0.3% | Apr 9, 2026 | flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key take... |
| CVE-2026-34500 | MEDIUM | 6.5 | 0.5% | Apr 9, 2026 | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Ap... |
| CVE-2026-32990 | MEDIUM | 5.3 | 0.3% | Apr 9, 2026 | Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects... |
| CVE-2026-25854 | MEDIUM | 6.1 | 0.5% | Apr 9, 2026 | Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDraini... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now