2026 CVE Vulnerabilities

51,132 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-41675HIGH7.5xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom...
CVE-2026-41674HIGH7.5xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom...
CVE-2026-41673HIGH7.5xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom...
CVE-2026-41672HIGH7.5xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom...
CVE-2026-41670HIGH8.2Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO...
CVE-2026-41669HIGH8.2Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implement...
CVE-2026-41660HIGH7.1Admidio is an open-source user management solution. Prior to version 5.0.9, a logic error in Admidio's two-factor authen...
CVE-2026-41640HIGH8.8NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-41587HIGH8.6CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-41142HIGH8.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-41002HIGH8.1The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git reposi...
CVE-2026-40981HIGH7.5When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the co...
CVE-2026-40004HIGH7.8There exists an openssl.cnf privilege escalation vulnerability in ZTE Cloud PC client uSmartview. An attacker can execut...
CVE-2026-8032HIGH7.3A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of...
CVE-2026-44118HIGH8.5OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request heade...
CVE-2026-44116HIGH8.6OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function t...
CVE-2026-44115HIGH8.8OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted ...
CVE-2026-44114HIGH8.5OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dot...
CVE-2026-44113HIGH8.3OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that al...
CVE-2026-44110HIGH8.8OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization th...
CVE-2026-43584HIGH8.8OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment p...
CVE-2026-43580HIGH7.7OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigat...
CVE-2026-43577HIGH7.1OpenClaw before 2026.4.9 contains a file read vulnerability allowing attackers to bypass navigation guards through brows...
CVE-2026-43576HIGH7.7OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoin...
CVE-2026-40326HIGH7.1Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the createBundle method in ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now