2026 CVE Vulnerabilities

53,500 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-32000HIGH7.1OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution t...
CVE-2026-31999HIGH7.8OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in ...
CVE-2026-31998HIGH8.6OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plu...
CVE-2026-31995HIGH7OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Wind...
CVE-2026-31994HIGH7.8OpenClaw versions prior to 2026.2.19 contain a local command injection vulnerability in Windows scheduled task script ge...
CVE-2026-31992HIGH8.8OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allows auth...
CVE-2026-31990HIGH7.1OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to valid...
CVE-2026-29607HIGH7.1OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persistence t...
CVE-2026-28461HIGH8.7OpenClaw versions prior to 2026.3.1 contain an unbounded memory growth vulnerability in the Zalo webhook endpoint that a...
CVE-2026-28460HIGH7.1OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers to ex...
CVE-2026-27566HIGH8.8OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fails to...
CVE-2026-22176HIGH7.8OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script generati...
CVE-2026-32255HIGH8.6Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has n...
CVE-2026-32805HIGH7.5Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for function...
CVE-2026-32730HIGH8.1ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication m...
CVE-2026-32944HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32886HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32878HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32770HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32728HIGH7.6Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32698HIGH7.2OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2...
CVE-2026-32636HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9...
CVE-2026-32321HIGH8.8ClipBucket v5 is an open source video sharing platform. An authenticated time-based blind SQL injection vulnerability ex...
CVE-2026-31973HIGH7.5SAMtools is a program for reading, manipulating and writing bioinformatics file formats. Starting in version 1.17, in th...
CVE-2026-4396HIGH8.1Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now