2026 CVE Vulnerabilities
51,238 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7412 | HIGH | 8.6 | 0.5% | May 5, 2026 | In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validat... |
| CVE-2026-43070 | HIGH | 7.8 | 0.1% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reset register ID for BPF_END value tracking ... |
| CVE-2026-43063 | HIGH | 7.8 | 0.1% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfs: don't irele after failing to iget in xfs_attri... |
| CVE-2026-43062 | HIGH | 7.1 | 0.2% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix type confusion in l2cap_ecred... |
| CVE-2026-43060 | HIGH | 7.8 | 0.1% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: drop pending enqueued packets on... |
| CVE-2026-43059 | HIGH | 7.8 | 0.1% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix list corruption and UAF in com... |
| CVE-2026-32689 | HIGH | 8.7 | 0.5% | May 5, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix allows a denial of servic... |
| CVE-2026-31196 | HIGH | 8.8 | 1.3% | May 5, 2026 | OS command injection vulnerability in the traceroute diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR Fr... |
| CVE-2026-31195 | HIGH | 8.8 | 1.3% | May 5, 2026 | OS command injection vulnerability in the ping diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR France G... |
| CVE-2026-4304 | HIGH | 7.5 | 0.3% | May 5, 2026 | The WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in all versions ... |
| CVE-2026-36355 | HIGH | 7.7 | 0.7% | May 5, 2026 | The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perfo... |
| CVE-2026-29168 | HIGH | 7.3 | 0.6% | May 5, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response dat... |
| CVE-2026-7833 | HIGH | 7.3 | 2.3% | May 5, 2026 | A weakness has been identified in EFM ipTIME C200 up to 1.092. This vulnerability affects the function sub_408F90 of the... |
| CVE-2026-7832 | HIGH | 7 | 0.1% | May 5, 2026 | A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of... |
| CVE-2026-6918 | HIGH | 7.5 | 0.5% | May 5, 2026 | In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte c... |
| CVE-2026-6261 | HIGH | 8.8 | 0.6% | May 5, 2026 | The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is d... |
| CVE-2026-43573 | HIGH | 7.7 | 0.3% | May 5, 2026 | OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser... |
| CVE-2026-43571 | HIGH | 8.8 | 0.4% | May 5, 2026 | OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to reso... |
| CVE-2026-43569 | HIGH | 8.8 | 0.4% | May 5, 2026 | OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto... |
| CVE-2026-43568 | HIGH | 7.1 | 0.2% | May 5, 2026 | OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators... |
| CVE-2026-43567 | HIGH | 7.1 | 0.2% | May 5, 2026 | OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that byp... |
| CVE-2026-43535 | HIGH | 8.1 | 0.2% | May 5, 2026 | OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allow... |
| CVE-2026-43533 | HIGH | 8.9 | 0.4% | May 5, 2026 | OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to ref... |
| CVE-2026-43532 | HIGH | 7.7 | 0.3% | May 5, 2026 | OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media proc... |
| CVE-2026-43531 | HIGH | 8.8 | 0.2% | May 5, 2026 | OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env file... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now