2026 CVE Vulnerabilities

52,167 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-6749HIGH7.5Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in ...
CVE-2026-6747HIGH7.5Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150...
CVE-2026-6746HIGH7.5Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firef...
CVE-2026-40520HIGH8.8FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() fun...
CVE-2026-41039HIGH7.5This vulnerability exists in Quantum Networks router due to improper access control and insecure default configuration i...
CVE-2026-41038HIGH8.8This vulnerability exists in Quantum Networks router due to lack of enforcement of strong password policies in the web-b...
CVE-2026-6553HIGH7.5Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and u...
CVE-2026-41037HIGH8.8This vulnerability exists in Quantum Networks router due to missing rate limiting and CAPTCHA protection for failed logi...
CVE-2026-41036HIGH8.8This vulnerability exists in Quantum Networks router due to inadequate sanitization of user-supplied input in the manage...
CVE-2026-39467HIGH7.2Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.Th...
CVE-2026-31368HIGH7.8AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service avail...
CVE-2026-40497HIGH8.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDanger...
CVE-2026-40250HIGH7.1OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-40244HIGH7.1OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-39973HIGH7.1Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability...
CVE-2026-39866HIGH8.8Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command...
CVE-2026-39386HIGH8.8Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 t...
CVE-2026-39320HIGH7.5Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to...
CVE-2026-41303HIGH8.8OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in Discord text approval commands that allows n...
CVE-2026-41299HIGH7.1OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only ...
CVE-2026-41297HIGH7.6OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functi...
CVE-2026-41296HIGH8.8OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile f...
CVE-2026-41295HIGH8.5OpenClaw before 2026.4.2 contains an improper trust boundary vulnerability allowing untrusted workspace channel shadows ...
CVE-2026-41294HIGH8.6OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing...
CVE-2026-35587HIGH8.8Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now