2026 CVE Vulnerabilities
53,691 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-29609 | HIGH | 8.7 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the fetchWithGuard function that alloc... |
| CVE-2026-28485 | HIGH | 7.8 | 0.2% | Mar 5, 2026 | OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control... |
| CVE-2026-28482 | HIGH | 8.4 | 0.1% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.12 construct transcript file paths using unsanitized sessionId parameters and sessionF... |
| CVE-2026-28481 | HIGH | 7.5 | 0.3% | Mar 5, 2026 | OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS... |
| CVE-2026-28478 | HIGH | 8.7 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request b... |
| CVE-2026-28477 | HIGH | 7.1 | 0.1% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login f... |
| CVE-2026-28473 | HIGH | 8.1 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scop... |
| CVE-2026-28469 | HIGH | 8.2 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a webhook routing vulnerability in the Google Chat monitor component that a... |
| CVE-2026-28468 | HIGH | 7.7 | 0.1% | Mar 5, 2026 | OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in wh... |
| CVE-2026-28467 | HIGH | 8.6 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydr... |
| CVE-2026-28465 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verifi... |
| CVE-2026-28464 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attacke... |
| CVE-2026-28459 | HIGH | 8.1 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway cli... |
| CVE-2026-28457 | HIGH | 7.9 | 0.1% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled)... |
| CVE-2026-28456 | HIGH | 8.6 | 0.4% | Mar 5, 2026 | OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently c... |
| CVE-2026-28450 | HIGH | 8.2 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /ap... |
| CVE-2026-29188 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2026-29081 | HIGH | 8.8 | 0.3% | Mar 5, 2026 | Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to... |
| CVE-2026-29077 | HIGH | 7.1 | 0.2% | Mar 5, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation wh... |
| CVE-2026-28442 | HIGH | 8.5 | 0.3% | Mar 5, 2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, u... |
| CVE-2026-28436 | HIGH | 7.2 | 0.2% | Mar 5, 2026 | Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted ... |
| CVE-2026-28410 | HIGH | 8.1 | 0.2% | Mar 5, 2026 | The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to ve... |
| CVE-2026-28790 | HIGH | 7.5 | 0.7% | Mar 5, 2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an ... |
| CVE-2026-28789 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated ... |
| CVE-2026-28342 | HIGH | 7.5 | 0.6% | Mar 5, 2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash AP... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now