2026 CVE Vulnerabilities
51,132 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41675 | HIGH | 7.5 | 0.4% | May 7, 2026 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom... |
| CVE-2026-41674 | HIGH | 7.5 | 0.5% | May 7, 2026 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom... |
| CVE-2026-41673 | HIGH | 7.5 | 0.6% | May 7, 2026 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom... |
| CVE-2026-41672 | HIGH | 7.5 | 0.4% | May 7, 2026 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom... |
| CVE-2026-41670 | HIGH | 8.2 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO... |
| CVE-2026-41669 | HIGH | 8.2 | 0.2% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implement... |
| CVE-2026-41660 | HIGH | 7.1 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, a logic error in Admidio's two-factor authen... |
| CVE-2026-41640 | HIGH | 8.8 | 1.9% | May 7, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-41587 | HIGH | 8.6 | 0.5% | May 7, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-41142 | HIGH | 8.8 | 0.4% | May 7, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-41002 | HIGH | 8.1 | 0.2% | May 7, 2026 | The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git reposi... |
| CVE-2026-40981 | HIGH | 7.5 | 0.4% | May 7, 2026 | When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the co... |
| CVE-2026-40004 | HIGH | 7.8 | 0.1% | May 7, 2026 | There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execut... |
| CVE-2026-8032 | HIGH | 7.3 | 0.3% | May 6, 2026 | A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of... |
| CVE-2026-44118 | HIGH | 8.5 | 0.1% | May 6, 2026 | OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request heade... |
| CVE-2026-44116 | HIGH | 8.6 | 0.3% | May 6, 2026 | OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function t... |
| CVE-2026-44115 | HIGH | 8.8 | 0.4% | May 6, 2026 | OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted ... |
| CVE-2026-44114 | HIGH | 8.5 | 0.1% | May 6, 2026 | OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dot... |
| CVE-2026-44113 | HIGH | 8.3 | 0.2% | May 6, 2026 | OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that al... |
| CVE-2026-44110 | HIGH | 8.8 | 0.3% | May 6, 2026 | OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization th... |
| CVE-2026-43584 | HIGH | 8.8 | 0.4% | May 6, 2026 | OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment p... |
| CVE-2026-43580 | HIGH | 7.7 | 0.3% | May 6, 2026 | OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigat... |
| CVE-2026-43577 | HIGH | 7.1 | 0.3% | May 6, 2026 | OpenClaw before 2026.4.9 contains a file read vulnerability allowing attackers to bypass navigation guards through brows... |
| CVE-2026-43576 | HIGH | 7.7 | 0.3% | May 6, 2026 | OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoin... |
| CVE-2026-40326 | HIGH | 7.1 | 0.2% | May 6, 2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the createBundle method in ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now