2026 CVE Vulnerabilities

51,727 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-7343HIGH7.5Use after free in Views in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker who had compromise...
CVE-2026-7342HIGH8.8Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbit...
CVE-2026-7341HIGH8.8Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code in...
CVE-2026-7339HIGH8.8Heap buffer overflow in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit...
CVE-2026-7338HIGH7.5Use after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to pote...
CVE-2026-7337HIGH8.8Type Confusion in V8 in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside...
CVE-2026-7336HIGH8.8Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code in...
CVE-2026-7335HIGH8.8Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-7334HIGH8.8Use after free in Views in Google Chrome on Mac prior to 147.0.7727.138 allowed a remote attacker to potentially exploit...
CVE-2026-42167HIGH8.1mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where th...
CVE-2026-7319HIGH7.3A flaw has been found in elinsky execution-system-mcp 0.1.0. The impacted element is the function _get_context_file_path...
CVE-2026-7316HIGH7.3A vulnerability has been found in eiliyaabedini aider-mcp up to 667b914301aada695aab0e46d1fb3a7d5e32c8af. Affected is an...
CVE-2026-7315HIGH7.3A flaw has been found in eiceblue spire-pdf-mcp-server 0.1.1. This impacts the function get_pdf_path of the file src/spi...
CVE-2026-7314HIGH7.3A vulnerability was detected in eiceblue spire-doc-mcp-server 1.0.0. This affects the function get_doc_path of the file ...
CVE-2026-41649HIGH7.7Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0...
CVE-2026-42432HIGH7.8OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect wit...
CVE-2026-42431HIGH8.1OpenClaw before 2026.4.8 contains a security bypass vulnerability in node.invoke(browser.proxy) that allows mutation of ...
CVE-2026-42429HIGH7.1OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechani...
CVE-2026-42428HIGH7.5OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can in...
CVE-2026-42426HIGH8.8OpenClaw before 2026.4.8 contains an improper authorization vulnerability where the node.pair.approve method accepts ope...
CVE-2026-42423HIGH7.7OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approva...
CVE-2026-42422HIGH8.8OpenClaw before 2026.4.8 contains a role bypass vulnerability in the device.token.rotate function that allows minting to...
CVE-2026-41914HIGH8.5OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass...
CVE-2026-41912HIGH7.6OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigge...
CVE-2026-41405HIGH8.7OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthentica...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now