2026 CVE Vulnerabilities

53,451 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-32025HIGH7.5OpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients that al...
CVE-2026-32024HIGH7.5OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows attackers ...
CVE-2026-32023HIGH7.1OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode where ...
CVE-2026-32017HIGH7.1OpenClaw versions prior to 2026.2.19 contain an allowlist bypass vulnerability in the exec safeBins policy that allows a...
CVE-2026-32016HIGH7.8OpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval allowl...
CVE-2026-32015HIGH7.8OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a path hijacking vulnerability in tools.exec.safeBins that allows...
CVE-2026-32014HIGH8.6OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and deviceFamily...
CVE-2026-32013HIGH8.8OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in the agents.files.get and agents.files....
CVE-2026-32011HIGH8.7OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Go...
CVE-2026-32010HIGH8.8OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safe-bin configuration when sort i...
CVE-2026-32009HIGH7.8OpenClaw versions prior to 2026.2.24 contain a policy bypass vulnerability in the safeBins allowlist evaluation that tru...
CVE-2026-32008HIGH7.1OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigat...
CVE-2026-32007HIGH8.1OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that al...
CVE-2026-32005HIGH8.1OpenClaw versions prior to 2026.2.25 fail to enforce sender authorization checks for interactive callbacks including blo...
CVE-2026-32004HIGH8.2OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route classifica...
CVE-2026-32003HIGH7.2OpenClaw versions prior to 2026.2.22 contain an environment variable injection vulnerability in the system.run function ...
CVE-2026-29072HIGH7.5Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who ...
CVE-2026-27934HIGH7.5Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack...
CVE-2026-3547HIGH7.5Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds re...
CVE-2026-33346HIGH8.7OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-33321HIGH7.6OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-33302HIGH8.1OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-33301HIGH8.1OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-32622HIGH8.8SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a S...
CVE-2026-26139HIGH8.6Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now