2026 CVE Vulnerabilities
51,727 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41395 | HIGH | 8.2 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes ... |
| CVE-2026-41394 | HIGH | 8.8 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes ... |
| CVE-2026-41392 | HIGH | 7.3 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains an exec allowlist bypass vulnerability allowing attackers to inherit allowlist trust ... |
| CVE-2026-41390 | HIGH | 7.3 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.28 contains an exec allowlist bypass vulnerability where allow-always persistence fails to unwrap... |
| CVE-2026-41387 | HIGH | 8.5 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.22 contains an incomplete host environment variable sanitization vulnerability in host-env-securi... |
| CVE-2026-41385 | HIGH | 7.1 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get me... |
| CVE-2026-41384 | HIGH | 8.5 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows... |
| CVE-2026-41383 | HIGH | 8.1 | 0.4% | Apr 28, 2026 | OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to ... |
| CVE-2026-41380 | HIGH | 7.3 | 0.1% | Apr 28, 2026 | OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-... |
| CVE-2026-41379 | HIGH | 7.1 | 0.2% | Apr 28, 2026 | OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write perm... |
| CVE-2026-41378 | HIGH | 8.8 | 0.4% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch... |
| CVE-2026-41375 | HIGH | 7.1 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints t... |
| CVE-2026-38949 | HIGH | 8.9 | 0.4% | Apr 28, 2026 | Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add... |
| CVE-2026-24222 | HIGH | 8.6 | 0.4% | Apr 28, 2026 | NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker co... |
| CVE-2026-24186 | HIGH | 8.8 | 0.5% | Apr 28, 2026 | NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sen... |
| CVE-2026-38651 | HIGH | 8.2 | 0.3% | Apr 28, 2026 | Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jw... |
| CVE-2026-7324 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presum... |
| CVE-2026-7323 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of me... |
| CVE-2026-7322 | HIGH | 7.3 | 0.3% | Apr 28, 2026 | Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of me... |
| CVE-2026-7320 | HIGH | 7.5 | 0.3% | Apr 28, 2026 | Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed i... |
| CVE-2026-7289 | HIGH | 8.8 | 0.7% | Apr 28, 2026 | A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/form... |
| CVE-2026-7288 | HIGH | 8.8 | 0.7% | Apr 28, 2026 | A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file... |
| CVE-2026-40968 | HIGH | 8.8 | 0.2% | Apr 28, 2026 | When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC wor... |
| CVE-2026-7272 | HIGH | 7.3 | 0.4% | Apr 28, 2026 | A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected e... |
| CVE-2026-5944 | HIGH | 8.2 | 0.5% | Apr 28, 2026 | An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now