2026 CVE Vulnerabilities
51,993 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41349 | HIGH | 8.8 | 0.5% | Apr 23, 2026 | OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execu... |
| CVE-2026-41347 | HIGH | 7.1 | 0.1% | Apr 23, 2026 | OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mod... |
| CVE-2026-41346 | HIGH | 7.5 | 0.4% | Apr 23, 2026 | OpenClaw 2026.2.26 before 2026.3.31 enforces pending pairing-request caps per channel file instead of per account, allow... |
| CVE-2026-41344 | HIGH | 8.8 | 0.2% | Apr 23, 2026 | OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the chat.send endpoint that allows write-scop... |
| CVE-2026-41342 | HIGH | 8.1 | 0.1% | Apr 23, 2026 | OpenClaw before 2026.3.28 contains an authentication bypass vulnerability in the remote onboarding component that persis... |
| CVE-2026-41336 | HIGH | 8.5 | 0.1% | Apr 23, 2026 | OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_HOOKS_DIR environment variable, e... |
| CVE-2026-41334 | HIGH | 7.1 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails to properly enforce... |
| CVE-2026-32210 | HIGH | 7.5 | 0.6% | Apr 23, 2026 | Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofin... |
| CVE-2026-32172 | HIGH | 8 | 0.3% | Apr 23, 2026 | Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network. |
| CVE-2026-6942 | HIGH | 8.8 | 1.9% | Apr 23, 2026 | radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to exe... |
| CVE-2026-6941 | HIGH | 7.8 | 0.2% | Apr 23, 2026 | radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to re... |
| CVE-2026-6940 | HIGH | 7.1 | 0.2% | Apr 23, 2026 | radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recurs... |
| CVE-2026-6376 | HIGH | 8.7 | 0.5% | Apr 23, 2026 | A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed using only ... |
| CVE-2026-6375 | HIGH | 8.7 | 0.3% | Apr 23, 2026 | A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without an... |
| CVE-2026-28525 | HIGH | 8.2 | 0.3% | Apr 23, 2026 | SWUpdate contains an integer underflow vulnerability in the multipart upload parser in mongoose_multipart.c that allows ... |
| CVE-2026-41279 | HIGH | 7.5 | 0.3% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-spe... |
| CVE-2026-41278 | HIGH | 7.5 | 0.4% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1... |
| CVE-2026-41277 | HIGH | 8.8 | 0.3% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignme... |
| CVE-2026-41275 | HIGH | 7.5 | 0.2% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password re... |
| CVE-2026-41273 | HIGH | 8.2 | 0.3% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contain... |
| CVE-2026-41272 | HIGH | 7.1 | 0.2% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core securi... |
| CVE-2026-41271 | HIGH | 8.3 | 0.2% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side R... |
| CVE-2026-41270 | HIGH | 8.3 | 0.2% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side R... |
| CVE-2026-41269 | HIGH | 8.8 | 0.5% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow co... |
| CVE-2026-41266 | HIGH | 7.5 | 0.3% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now