2026 CVE Vulnerabilities

53,128 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-33618HIGH8.8Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray...
CVE-2026-40163HIGH8.2Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, t...
CVE-2026-40162HIGH7.1Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugs...
CVE-2026-32931HIGH8.8Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability ...
CVE-2026-32930HIGH7.1Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR)...
CVE-2026-32894HIGH7.1Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR)...
CVE-2026-32892HIGH8.8Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injecti...
CVE-2026-31940HIGH8.8Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled ...
CVE-2026-31939HIGH8.3Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php...
CVE-2026-40200HIGH8.1An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very ...
CVE-2026-40158HIGH7.8PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using ty...
CVE-2026-40157HIGH8.8PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives u...
CVE-2026-40156HIGH7.8PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file named tools.py from the ...
CVE-2026-40074HIGH7.5SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, redir...
CVE-2026-40073HIGH7.5SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under...
CVE-2026-35670HIGH8.1OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to rebind chat replies t...
CVE-2026-35669HIGH8.8OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that...
CVE-2026-35668HIGH7.7OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sandboxed agents to re...
CVE-2026-35666HIGH8.8OpenClaw before 2026.3.22 contains an allowlist bypass vulnerability in system.run approvals that fails to unwrap /usr/b...
CVE-2026-35663HIGH8.8OpenClaw before 2026.3.25 contains a privilege escalation vulnerability allowing non-admin operators to self-request bro...
CVE-2026-35660HIGH8.1OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent /reset endpoint tha...
CVE-2026-35657HIGH7.1OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sessionKey/history route...
CVE-2026-35653HIGH8.1OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that all...
CVE-2026-35650HIGH8.8OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypa...
CVE-2026-35643HIGH8.8OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now