2026 CVE Vulnerabilities

53,133 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-5985HIGH7.3A security flaw has been discovered in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown ...
CVE-2026-5295HIGH8A stack buffer overflow exists in wolfSSL's PKCS7 implementation in the wc_PKCS7_DecryptOri() function in wolfcrypt/src/...
CVE-2026-5984HIGH8.8A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of the file /goform/formS...
CVE-2026-5983HIGH8.8A vulnerability was determined in D-Link DIR-605L 2.13B01. This issue affects the function formSetDDNS of the file /gofo...
CVE-2026-5982HIGH8.8A vulnerability was found in D-Link DIR-605L 2.13B01. This vulnerability affects the function formAdvNetwork of the file...
CVE-2026-5981HIGH8.8A vulnerability has been found in D-Link DIR-605L 2.13B01. This affects the function formAdvFirewall of the file /goform...
CVE-2026-40149HIGH7.3PraisonAI is a multi-agent teams system. Prior to 4.5.128, the gateway's /api/approval/allow-list endpoint permits unaut...
CVE-2026-40117HIGH7.5PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py allows reading arbi...
CVE-2026-40116HIGH7.5PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /media-stream WebSocket endpoint in PraisonAI's call modu...
CVE-2026-40115HIGH7.5PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (server.py) reads the e...
CVE-2026-40113HIGH8.1PraisonAI is a multi-agent teams system. Prior to 4.5.128, deploy.py constructs a single comma-delimited string for the ...
CVE-2026-40111HIGH8.8PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he memory hooks executor in praisonaiagents passes a us...
CVE-2026-35645HIGH8.8OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSe...
CVE-2026-35644HIGH7.1OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scop...
CVE-2026-35640HIGH7.5OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook signatures, allowing unauthenticated atta...
CVE-2026-35639HIGH8.8OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an...
CVE-2026-35638HIGH8.8OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated se...
CVE-2026-35637HIGH7.3OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowing cite w...
CVE-2026-35636HIGH7.1OpenClaw versions 2026.3.11 through 2026.3.24 contain a session isolation bypass vulnerability where session_status reso...
CVE-2026-35632HIGH7.8OpenClaw through 2026.2.22 contains a symlink traversal vulnerability in agents.create and agents.update handlers that u...
CVE-2026-35631HIGH7.1OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unautho...
CVE-2026-35629HIGH7.4OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail ...
CVE-2026-35627HIGH8.2OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforci...
CVE-2026-35625HIGH8.5OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-a...
CVE-2026-35622HIGH7.1OpenClaw before 2026.3.22 contains an improper authentication verification vulnerability in Google Chat app-url webhook ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now