2026 CVE Vulnerabilities

51,208 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-29105MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29100MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM 7.15....
CVE-2026-29098MEDIUM4.9SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29096MEDIUM6.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-33410MEDIUM5.4Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have two au...
CVE-2026-33393MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `allow...
CVE-2026-33355MEDIUM6.5Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `/priv...
CVE-2026-32753MEDIUM5.4FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, bypass...
CVE-2026-32750MEDIUM6.8SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the l...
CVE-2026-32099MEDIUM6.5Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, when a use...
CVE-2026-32040MEDIUM6.1OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows at...
CVE-2026-32039MEDIUM6.5OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy mat...
CVE-2026-32037MEDIUM6.5OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts al...
CVE-2026-32033MEDIUM6.5OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass works...
CVE-2026-32031MEDIUM6.5OpenClaw versions prior to 2026.2.26 server-http contains an authentication bypass vulnerability in gateway authenticati...
CVE-2026-32029MEDIUM6.3OpenClaw versions prior to 2026.2.21 improperly parse the left-most X-Forwarded-For header value when requests originate...
CVE-2026-32028MEDIUM6.3OpenClaw versions prior to 2026.2.25 fail to enforce dmPolicy and allowFrom authorization checks on Discord direct-messa...
CVE-2026-32022MEDIUM6.5OpenClaw versions prior to 2026.2.21 contain a stdin-only policy bypass vulnerability in the grep tool within tools.exec...
CVE-2026-32021MEDIUM6.5OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowlist imp...
CVE-2026-32020MEDIUM5.5OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symb...
CVE-2026-32019MEDIUM5.3OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() functio...
CVE-2026-32018MEDIUM4.8OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and removeRegis...
CVE-2026-32006MEDIUM4.3OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are...
CVE-2026-32002MEDIUM6.5OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails to en...
CVE-2026-32001MEDIUM5.4OpenClaw versions prior to 2026.2.22 contain an authentication bypass vulnerability that allows clients authenticated wi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now