2026 CVE Vulnerabilities
53,133 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5985 | HIGH | 7.3 | 0.3% | Apr 9, 2026 | A security flaw has been discovered in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown ... |
| CVE-2026-5295 | HIGH | 8 | 0.2% | Apr 9, 2026 | A stack buffer overflow exists in wolfSSL's PKCS7 implementation in the wc_PKCS7_DecryptOri() function in wolfcrypt/src/... |
| CVE-2026-5984 | HIGH | 8.8 | 0.8% | Apr 9, 2026 | A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of the file /goform/formS... |
| CVE-2026-5983 | HIGH | 8.8 | 0.7% | Apr 9, 2026 | A vulnerability was determined in D-Link DIR-605L 2.13B01. This issue affects the function formSetDDNS of the file /gofo... |
| CVE-2026-5982 | HIGH | 8.8 | 0.7% | Apr 9, 2026 | A vulnerability was found in D-Link DIR-605L 2.13B01. This vulnerability affects the function formAdvNetwork of the file... |
| CVE-2026-5981 | HIGH | 8.8 | 0.7% | Apr 9, 2026 | A vulnerability has been found in D-Link DIR-605L 2.13B01. This affects the function formAdvFirewall of the file /goform... |
| CVE-2026-40149 | HIGH | 7.3 | 0.2% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the gateway's /api/approval/allow-list endpoint permits unaut... |
| CVE-2026-40117 | HIGH | 7.5 | 0.2% | Apr 9, 2026 | PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py allows reading arbi... |
| CVE-2026-40116 | HIGH | 7.5 | 0.4% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /media-stream WebSocket endpoint in PraisonAI's call modu... |
| CVE-2026-40115 | HIGH | 7.5 | 0.3% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (server.py) reads the e... |
| CVE-2026-40113 | HIGH | 8.1 | 0.2% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, deploy.py constructs a single comma-delimited string for the ... |
| CVE-2026-40111 | HIGH | 8.8 | 0.2% | Apr 9, 2026 | PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he memory hooks executor in praisonaiagents passes a us... |
| CVE-2026-35645 | HIGH | 8.8 | 0.3% | Apr 9, 2026 | OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSe... |
| CVE-2026-35644 | HIGH | 7.1 | 0.2% | Apr 9, 2026 | OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scop... |
| CVE-2026-35640 | HIGH | 7.5 | 0.4% | Apr 9, 2026 | OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook signatures, allowing unauthenticated atta... |
| CVE-2026-35639 | HIGH | 8.8 | 0.5% | Apr 9, 2026 | OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an... |
| CVE-2026-35638 | HIGH | 8.8 | 0.3% | Apr 9, 2026 | OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated se... |
| CVE-2026-35637 | HIGH | 7.3 | 0.2% | Apr 9, 2026 | OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowing cite w... |
| CVE-2026-35636 | HIGH | 7.1 | 0.3% | Apr 9, 2026 | OpenClaw versions 2026.3.11 through 2026.3.24 contain a session isolation bypass vulnerability where session_status reso... |
| CVE-2026-35632 | HIGH | 7.8 | 0.3% | Apr 9, 2026 | OpenClaw through 2026.2.22 contains a symlink traversal vulnerability in agents.create and agents.update handlers that u... |
| CVE-2026-35631 | HIGH | 7.1 | 0.2% | Apr 9, 2026 | OpenClaw before 2026.3.22 fails to enforce operator.admin scope on mutating internal ACP chat commands, allowing unautho... |
| CVE-2026-35629 | HIGH | 7.4 | 0.2% | Apr 9, 2026 | OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail ... |
| CVE-2026-35627 | HIGH | 8.2 | 0.5% | Apr 9, 2026 | OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforci... |
| CVE-2026-35625 | HIGH | 8.5 | 0.2% | Apr 9, 2026 | OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-a... |
| CVE-2026-35622 | HIGH | 7.1 | 0.3% | Apr 9, 2026 | OpenClaw before 2026.3.22 contains an improper authentication verification vulnerability in Google Chat app-url webhook ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now