2026 CVE Vulnerabilities
51,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43535 | HIGH | 8.1 | 0.2% | May 5, 2026 | OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allow... |
| CVE-2026-43533 | HIGH | 8.9 | 0.4% | May 5, 2026 | OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to ref... |
| CVE-2026-43532 | HIGH | 7.7 | 0.3% | May 5, 2026 | OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media proc... |
| CVE-2026-43531 | HIGH | 8.8 | 0.2% | May 5, 2026 | OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env file... |
| CVE-2026-43530 | HIGH | 8.8 | 0.4% | May 5, 2026 | OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybo... |
| CVE-2026-43528 | HIGH | 7.1 | 0.3% | May 5, 2026 | OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive... |
| CVE-2026-43527 | HIGH | 7.7 | 0.3% | May 5, 2026 | OpenClaw before 2026.4.14 contains a server-side request forgery vulnerability in browser SSRF policy that allows privat... |
| CVE-2026-42439 | HIGH | 8.5 | 0.2% | May 5, 2026 | OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action ... |
| CVE-2026-42438 | HIGH | 7.7 | 0.2% | May 5, 2026 | OpenClaw versions 2026.4.9 before 2026.4.10 contain a sender policy bypass vulnerability in the outbound host-media atta... |
| CVE-2026-42437 | HIGH | 8.2 | 0.4% | May 5, 2026 | OpenClaw versions 2026.4.9 before 2026.4.10 contain a denial of service vulnerability in the voice-call realtime WebSock... |
| CVE-2026-42436 | HIGH | 7.7 | 0.3% | May 5, 2026 | OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab rou... |
| CVE-2026-42435 | HIGH | 8.8 | 0.4% | May 5, 2026 | OpenClaw versions from 2026.2.22 before 2026.4.12 contain an insufficient shell-wrapper detection vulnerability allowing... |
| CVE-2026-42434 | HIGH | 8.8 | 0.3% | May 5, 2026 | OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override... |
| CVE-2026-42433 | HIGH | 7.1 | 0.3% | May 5, 2026 | OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to a... |
| CVE-2026-6322 | HIGH | 7.5 | 0.5% | May 5, 2026 | fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as ... |
| CVE-2026-43870 | HIGH | 7.3 | 0.4% | May 5, 2026 | Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutra... |
| CVE-2026-3359 | HIGH | 7.5 | 0.4% | May 5, 2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Inj... |
| CVE-2026-43869 | HIGH | 7.3 | 0.6% | May 5, 2026 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift:... |
| CVE-2026-6180 | HIGH | 8.1 | 0.2% | May 5, 2026 | A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under spe... |
| CVE-2026-5192 | HIGH | 7.5 | 0.8% | May 5, 2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Trave... |
| CVE-2026-7812 | HIGH | 7.3 | 1.3% | May 5, 2026 | A vulnerability was found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The impacted element is the... |
| CVE-2026-7811 | HIGH | 7.3 | 0.4% | May 5, 2026 | A vulnerability has been found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The affected element i... |
| CVE-2026-7810 | HIGH | 7.3 | 0.4% | May 5, 2026 | A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the fu... |
| CVE-2026-4803 | HIGH | 7.2 | 0.4% | May 5, 2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter ... |
| CVE-2026-3456 | HIGH | 7.5 | 0.3% | May 5, 2026 | The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now