2026 CVE Vulnerabilities

51,993 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-41349HIGH8.8OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execu...
CVE-2026-41347HIGH7.1OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mod...
CVE-2026-41346HIGH7.5OpenClaw 2026.2.26 before 2026.3.31 enforces pending pairing-request caps per channel file instead of per account, allow...
CVE-2026-41344HIGH8.8OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the chat.send endpoint that allows write-scop...
CVE-2026-41342HIGH8.1OpenClaw before 2026.3.28 contains an authentication bypass vulnerability in the remote onboarding component that persis...
CVE-2026-41336HIGH8.5OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_HOOKS_DIR environment variable, e...
CVE-2026-41334HIGH7.1OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails to properly enforce...
CVE-2026-32210HIGH7.5Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofin...
CVE-2026-32172HIGH8Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.
CVE-2026-6942HIGH8.8radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to exe...
CVE-2026-6941HIGH7.8radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to re...
CVE-2026-6940HIGH7.1radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recurs...
CVE-2026-6376HIGH8.7A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed using only ...
CVE-2026-6375HIGH8.7A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without an...
CVE-2026-28525HIGH8.2SWUpdate contains an integer underflow vulnerability in the multipart upload parser in mongoose_multipart.c that allows ...
CVE-2026-41279HIGH7.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-spe...
CVE-2026-41278HIGH7.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1...
CVE-2026-41277HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignme...
CVE-2026-41275HIGH7.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password re...
CVE-2026-41273HIGH8.2Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contain...
CVE-2026-41272HIGH7.1Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core securi...
CVE-2026-41271HIGH8.3Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side R...
CVE-2026-41270HIGH8.3Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side R...
CVE-2026-41269HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow co...
CVE-2026-41266HIGH7.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now