2026 CVE Vulnerabilities
53,500 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32000 | HIGH | 7.1 | 0.6% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution t... |
| CVE-2026-31999 | HIGH | 7.8 | 0.2% | Mar 19, 2026 | OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in ... |
| CVE-2026-31998 | HIGH | 8.6 | 0.3% | Mar 19, 2026 | OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plu... |
| CVE-2026-31995 | HIGH | 7 | 0.5% | Mar 19, 2026 | OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Wind... |
| CVE-2026-31994 | HIGH | 7.8 | 0.6% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.19 contain a local command injection vulnerability in Windows scheduled task script ge... |
| CVE-2026-31992 | HIGH | 8.8 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allows auth... |
| CVE-2026-31990 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to valid... |
| CVE-2026-29607 | HIGH | 7.1 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persistence t... |
| CVE-2026-28461 | HIGH | 8.7 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.1 contain an unbounded memory growth vulnerability in the Zalo webhook endpoint that a... |
| CVE-2026-28460 | HIGH | 7.1 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers to ex... |
| CVE-2026-27566 | HIGH | 8.8 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fails to... |
| CVE-2026-22176 | HIGH | 7.8 | 0.6% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script generati... |
| CVE-2026-32255 | HIGH | 8.6 | 10.1% | Mar 19, 2026 | Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has n... |
| CVE-2026-32805 | HIGH | 7.5 | 0.4% | Mar 18, 2026 | Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for function... |
| CVE-2026-32730 | HIGH | 8.1 | 0.4% | Mar 18, 2026 | ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication m... |
| CVE-2026-32944 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32886 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32878 | HIGH | 7.5 | 0.3% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32770 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32728 | HIGH | 7.6 | 0.3% | Mar 18, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-32698 | HIGH | 7.2 | 0.3% | Mar 18, 2026 | OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2... |
| CVE-2026-32636 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9... |
| CVE-2026-32321 | HIGH | 8.8 | 0.4% | Mar 18, 2026 | ClipBucket v5 is an open source video sharing platform. An authenticated time-based blind SQL injection vulnerability ex... |
| CVE-2026-31973 | HIGH | 7.5 | 0.5% | Mar 18, 2026 | SAMtools is a program for reading, manipulating and writing bioinformatics file formats. Starting in version 1.17, in th... |
| CVE-2026-4396 | HIGH | 8.1 | 0.1% | Mar 18, 2026 | Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now