2026 CVE Vulnerabilities

53,691 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-29609HIGH8.7OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the fetchWithGuard function that alloc...
CVE-2026-28485HIGH7.8OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control...
CVE-2026-28482HIGH8.4OpenClaw versions prior to 2026.2.12 construct transcript file paths using unsanitized sessionId parameters and sessionF...
CVE-2026-28481HIGH7.5OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS...
CVE-2026-28478HIGH8.7OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request b...
CVE-2026-28477HIGH7.1OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login f...
CVE-2026-28473HIGH8.1OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scop...
CVE-2026-28469HIGH8.2OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that a...
CVE-2026-28468HIGH7.7OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in wh...
CVE-2026-28467HIGH8.6OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydr...
CVE-2026-28465HIGH7.5OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verifi...
CVE-2026-28464HIGH7.5OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attacke...
CVE-2026-28459HIGH8.1OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway cli...
CVE-2026-28457HIGH7.9OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled)...
CVE-2026-28456HIGH8.6OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently c...
CVE-2026-28450HIGH8.2OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /ap...
CVE-2026-29188HIGH8.1File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2026-29081HIGH8.8Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to...
CVE-2026-29077HIGH7.1Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation wh...
CVE-2026-28442HIGH8.5ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, u...
CVE-2026-28436HIGH7.2Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted ...
CVE-2026-28410HIGH8.1The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to ve...
CVE-2026-28790HIGH7.5OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an ...
CVE-2026-28789HIGH7.5OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated ...
CVE-2026-28342HIGH7.5OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash AP...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now