2026 CVE Vulnerabilities
53,128 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33618 | HIGH | 8.8 | 0.3% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray... |
| CVE-2026-40163 | HIGH | 8.2 | 0.3% | Apr 10, 2026 | Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, t... |
| CVE-2026-40162 | HIGH | 7.1 | 0.3% | Apr 10, 2026 | Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugs... |
| CVE-2026-32931 | HIGH | 8.8 | 0.5% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability ... |
| CVE-2026-32930 | HIGH | 7.1 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR)... |
| CVE-2026-32894 | HIGH | 7.1 | 0.3% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR)... |
| CVE-2026-32892 | HIGH | 8.8 | 1.5% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injecti... |
| CVE-2026-31940 | HIGH | 8.8 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled ... |
| CVE-2026-31939 | HIGH | 8.3 | 0.4% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php... |
| CVE-2026-40200 | HIGH | 8.1 | 0.1% | Apr 10, 2026 | An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very ... |
| CVE-2026-40158 | HIGH | 7.8 | 0.2% | Apr 10, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using ty... |
| CVE-2026-40157 | HIGH | 8.8 | 0.4% | Apr 10, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives u... |
| CVE-2026-40156 | HIGH | 7.8 | 0.2% | Apr 10, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file named tools.py from the ... |
| CVE-2026-40074 | HIGH | 7.5 | 0.4% | Apr 10, 2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, redir... |
| CVE-2026-40073 | HIGH | 7.5 | 0.5% | Apr 10, 2026 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under... |
| CVE-2026-35670 | HIGH | 8.1 | 0.2% | Apr 10, 2026 | OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to rebind chat replies t... |
| CVE-2026-35669 | HIGH | 8.8 | 0.3% | Apr 10, 2026 | OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that... |
| CVE-2026-35668 | HIGH | 7.7 | 0.4% | Apr 10, 2026 | OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sandboxed agents to re... |
| CVE-2026-35666 | HIGH | 8.8 | 0.4% | Apr 10, 2026 | OpenClaw before 2026.3.22 contains an allowlist bypass vulnerability in system.run approvals that fails to unwrap /usr/b... |
| CVE-2026-35663 | HIGH | 8.8 | 0.3% | Apr 10, 2026 | OpenClaw before 2026.3.25 contains a privilege escalation vulnerability allowing non-admin operators to self-request bro... |
| CVE-2026-35660 | HIGH | 8.1 | 0.3% | Apr 10, 2026 | OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent /reset endpoint tha... |
| CVE-2026-35657 | HIGH | 7.1 | 0.2% | Apr 10, 2026 | OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sessionKey/history route... |
| CVE-2026-35653 | HIGH | 8.1 | 0.6% | Apr 10, 2026 | OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that all... |
| CVE-2026-35650 | HIGH | 8.8 | 0.5% | Apr 10, 2026 | OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypa... |
| CVE-2026-35643 | HIGH | 8.8 | 0.4% | Apr 10, 2026 | OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now