2026 CVE Vulnerabilities

51,727 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-41395HIGH8.2OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes ...
CVE-2026-41394HIGH8.8OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes ...
CVE-2026-41392HIGH7.3OpenClaw before 2026.3.31 contains an exec allowlist bypass vulnerability allowing attackers to inherit allowlist trust ...
CVE-2026-41390HIGH7.3OpenClaw before 2026.3.28 contains an exec allowlist bypass vulnerability where allow-always persistence fails to unwrap...
CVE-2026-41387HIGH8.5OpenClaw before 2026.3.22 contains an incomplete host environment variable sanitization vulnerability in host-env-securi...
CVE-2026-41385HIGH7.1OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get me...
CVE-2026-41384HIGH8.5OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows...
CVE-2026-41383HIGH8.1OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to ...
CVE-2026-41380HIGH7.3OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-...
CVE-2026-41379HIGH7.1OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write perm...
CVE-2026-41378HIGH8.8OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch...
CVE-2026-41375HIGH7.1OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints t...
CVE-2026-38949HIGH8.9Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add...
CVE-2026-24222HIGH8.6NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker co...
CVE-2026-24186HIGH8.8NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sen...
CVE-2026-38651HIGH8.2Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jw...
CVE-2026-7324HIGH7.3Memory safety bugs present in Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presum...
CVE-2026-7323HIGH7.3Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of me...
CVE-2026-7322HIGH7.3Memory safety bugs present in Thunderbird ESR 140.10.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of me...
CVE-2026-7320HIGH7.5Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed i...
CVE-2026-7289HIGH8.8A vulnerability was found in D-Link DIR-825M 1.1.12. This issue affects the function sub_414BA8 of the file /boafrm/form...
CVE-2026-7288HIGH8.8A vulnerability has been found in D-Link DIR-825M 1.1.12. This vulnerability affects the function sub_4151FC of the file...
CVE-2026-40968HIGH8.8When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC wor...
CVE-2026-7272HIGH7.3A flaw has been found in WilliamCloudQi matlab-mcp-server up to ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca. The affected e...
CVE-2026-5944HIGH8.2An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now