2026 CVE Vulnerabilities

51,238 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-7412HIGH8.6In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validat...
CVE-2026-43070HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Reset register ID for BPF_END value tracking ...
CVE-2026-43063HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfs: don't irele after failing to iget in xfs_attri...
CVE-2026-43062HIGH7.1In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix type confusion in l2cap_ecred...
CVE-2026-43060HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: drop pending enqueued packets on...
CVE-2026-43059HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix list corruption and UAF in com...
CVE-2026-32689HIGH8.7Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix allows a denial of servic...
CVE-2026-31196HIGH8.8OS command injection vulnerability in the traceroute diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR Fr...
CVE-2026-31195HIGH8.8OS command injection vulnerability in the ping diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR France G...
CVE-2026-4304HIGH7.5The WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in all versions ...
CVE-2026-36355HIGH7.7The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perfo...
CVE-2026-29168HIGH7.3Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's  mod_md via OCSP response dat...
CVE-2026-7833HIGH7.3A weakness has been identified in EFM ipTIME C200 up to 1.092. This vulnerability affects the function sub_408F90 of the...
CVE-2026-7832HIGH7A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of...
CVE-2026-6918HIGH7.5In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte c...
CVE-2026-6261HIGH8.8The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is d...
CVE-2026-43573HIGH7.7OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser...
CVE-2026-43571HIGH8.8OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to reso...
CVE-2026-43569HIGH8.8OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto...
CVE-2026-43568HIGH7.1OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators...
CVE-2026-43567HIGH7.1OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that byp...
CVE-2026-43535HIGH8.1OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allow...
CVE-2026-43533HIGH8.9OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to ref...
CVE-2026-43532HIGH7.7OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media proc...
CVE-2026-43531HIGH8.8OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env file...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now