2026 CVE Vulnerabilities

64,729 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-100556MEDIUM6.3OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in ...
CVE-2026-100554MEDIUM4.2OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authori...
CVE-2026-100553MEDIUM4.3OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feis...
CVE-2026-100550MEDIUM5.4OpenClaw (npm package 'openclaw') before 2026.8.1 contains an access-control bypass in the Microsoft Teams integration. ...
CVE-2026-100549MEDIUM5.4OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in QQBot voice attachment handling where filena...
CVE-2026-100548MEDIUM5.3OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 contain a credential exposure issue in memory emb...
CVE-2026-100547MEDIUM5.5OpenClaw is a coding agent distributed as the npm package `openclaw`. In affected versions (2026.7.1 through 2026.7.2), ...
CVE-2026-100546MEDIUM6.4OpenClaw (npm package `openclaw`) versions >= 2026.7.2 and < 2026.9.2 contain a race condition in the Discord realtime v...
CVE-2026-100545MEDIUM5.3OpenClaw (npm package `openclaw`) before 2026.8.1 incorrectly enforces sender tool policies during session-memory filena...
CVE-2026-100540MEDIUM6.8OpenClaw Feishu before 2026.8.1 fails to validate whether a configured default account is disabled before selecting it f...
CVE-2026-100538MEDIUM6.5OpenClaw (npm package 'openclaw') before 2026.8.1 does not apply the originating sender's global or per-agent toolsBySen...
CVE-2026-100536MEDIUM6.5OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attacke...
CVE-2026-100533MEDIUM5.3OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Uni...
CVE-2026-100531MEDIUM6.5The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when ...
CVE-2026-100529MEDIUM6.4OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always ap...
CVE-2026-100528MEDIUM5.4OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In ...
CVE-2026-100527MEDIUM5.3OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthent...
CVE-2026-100526MEDIUM5.3OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped medi...
CVE-2026-100525MEDIUM4.3The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce t...
CVE-2026-100524MEDIUM5.4Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attacker...
CVE-2026-100523MEDIUM6.1Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter ...
CVE-2026-100522MEDIUM6.1Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is ...
CVE-2026-100521MEDIUM6.1Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter t...
CVE-2026-100505MEDIUM4.4Ghidra versions 11.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when ...
CVE-2026-86066MEDIUM5.9Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now