2026 CVE Vulnerabilities

51,261 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-43535HIGH8.1OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allow...
CVE-2026-43533HIGH8.9OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to ref...
CVE-2026-43532HIGH7.7OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media proc...
CVE-2026-43531HIGH8.8OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env file...
CVE-2026-43530HIGH8.8OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybo...
CVE-2026-43528HIGH7.1OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive...
CVE-2026-43527HIGH7.7OpenClaw before 2026.4.14 contains a server-side request forgery vulnerability in browser SSRF policy that allows privat...
CVE-2026-42439HIGH8.5OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action ...
CVE-2026-42438HIGH7.7OpenClaw versions 2026.4.9 before 2026.4.10 contain a sender policy bypass vulnerability in the outbound host-media atta...
CVE-2026-42437HIGH8.2OpenClaw versions 2026.4.9 before 2026.4.10 contain a denial of service vulnerability in the voice-call realtime WebSock...
CVE-2026-42436HIGH7.7OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab rou...
CVE-2026-42435HIGH8.8OpenClaw versions from 2026.2.22 before 2026.4.12 contain an insufficient shell-wrapper detection vulnerability allowing...
CVE-2026-42434HIGH8.8OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override...
CVE-2026-42433HIGH7.1OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to a...
CVE-2026-6322HIGH7.5fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as ...
CVE-2026-43870HIGH7.3Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutra...
CVE-2026-3359HIGH7.5The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Inj...
CVE-2026-43869HIGH7.3Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift:...
CVE-2026-6180HIGH8.1A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under spe...
CVE-2026-5192HIGH7.5The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Trave...
CVE-2026-7812HIGH7.3A vulnerability was found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The impacted element is the...
CVE-2026-7811HIGH7.3A vulnerability has been found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The affected element i...
CVE-2026-7810HIGH7.3A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the fu...
CVE-2026-4803HIGH7.2The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter ...
CVE-2026-3456HIGH7.5The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now