2026 CVE Vulnerabilities

51,238 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-32031MEDIUM6.5OpenClaw versions prior to 2026.2.26 server-http contains an authentication bypass vulnerability in gateway authenticati...
CVE-2026-32029MEDIUM6.3OpenClaw versions prior to 2026.2.21 improperly parse the left-most X-Forwarded-For header value when requests originate...
CVE-2026-32028MEDIUM6.3OpenClaw versions prior to 2026.2.25 fail to enforce dmPolicy and allowFrom authorization checks on Discord direct-messa...
CVE-2026-32022MEDIUM6.5OpenClaw versions prior to 2026.2.21 contain a stdin-only policy bypass vulnerability in the grep tool within tools.exec...
CVE-2026-32021MEDIUM6.5OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowlist imp...
CVE-2026-32020MEDIUM5.5OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symb...
CVE-2026-32019MEDIUM5.3OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() functio...
CVE-2026-32018MEDIUM4.8OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and removeRegis...
CVE-2026-32006MEDIUM4.3OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are...
CVE-2026-32002MEDIUM6.5OpenClaw versions prior to 2026.2.23 contain a sandbox bypass vulnerability in the sandboxed image tool that fails to en...
CVE-2026-32001MEDIUM5.4OpenClaw versions prior to 2026.2.22 contain an authentication bypass vulnerability that allows clients authenticated wi...
CVE-2026-30873MEDIUM4.9OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to both 24.10.6 and 25.12.1, t...
CVE-2026-28282MEDIUM6.5Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a secu...
CVE-2026-27936MEDIUM5.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restrict...
CVE-2026-27935MEDIUM6.5Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vuln...
CVE-2026-3229MEDIUM5.5An integer overflow vulnerability existed in the static function wolfssl_add_to_chain, that caused heap corruption when ...
CVE-2026-33305MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-33304MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-33303MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ...
CVE-2026-33299MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-32747MEDIUM4.9SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the globalCopyFiles API eads source file...
CVE-2026-27740MEDIUM6.1Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cros...
CVE-2026-27570MEDIUM6.1Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox...
CVE-2026-27491MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coe...
CVE-2026-27454MEDIUM5.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now