2026 CVE Vulnerabilities
53,709 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28464 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attacke... |
| CVE-2026-28459 | HIGH | 8.1 | 0.4% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway cli... |
| CVE-2026-28457 | HIGH | 7.9 | 0.1% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled)... |
| CVE-2026-28456 | HIGH | 8.6 | 0.4% | Mar 5, 2026 | OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently c... |
| CVE-2026-28450 | HIGH | 8.2 | 0.3% | Mar 5, 2026 | OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /ap... |
| CVE-2026-29188 | HIGH | 8.1 | 0.5% | Mar 5, 2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2026-29081 | HIGH | 8.8 | 0.3% | Mar 5, 2026 | Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to... |
| CVE-2026-29077 | HIGH | 7.1 | 0.2% | Mar 5, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation wh... |
| CVE-2026-28442 | HIGH | 8.5 | 0.3% | Mar 5, 2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, u... |
| CVE-2026-28436 | HIGH | 7.2 | 0.2% | Mar 5, 2026 | Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted ... |
| CVE-2026-28410 | HIGH | 8.1 | 0.2% | Mar 5, 2026 | The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to ve... |
| CVE-2026-28790 | HIGH | 7.5 | 0.7% | Mar 5, 2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an ... |
| CVE-2026-28789 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated ... |
| CVE-2026-28342 | HIGH | 7.5 | 0.6% | Mar 5, 2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash AP... |
| CVE-2026-28277 | HIGH | 7.2 | 5.2% | Mar 5, 2026 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ... |
| CVE-2026-3459 | HIGH | 8.1 | 0.6% | Mar 5, 2026 | The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due... |
| CVE-2026-3047 | HIGH | 8.8 | 0.5% | Mar 5, 2026 | A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is config... |
| CVE-2026-3009 | HIGH | 8.1 | 0.3% | Mar 5, 2026 | A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an... |
| CVE-2026-29054 | HIGH | 7.5 | 0.5% | Mar 5, 2026 | Traefik is an HTTP reverse proxy and load balancer. From version 2.11.9 to 2.11.37 and from version 3.1.3 to 3.6.8, ther... |
| CVE-2026-28287 | HIGH | 8.8 | 8.5% | Mar 5, 2026 | FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, ... |
| CVE-2026-28284 | HIGH | 8.8 | 0.2% | Mar 5, 2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several aut... |
| CVE-2026-28210 | HIGH | 8.8 | 0.3% | Mar 5, 2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnera... |
| CVE-2026-28209 | HIGH | 7.2 | 0.9% | Mar 5, 2026 | FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, ... |
| CVE-2026-26999 | HIGH | 7.5 | 0.5% | Mar 5, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerabil... |
| CVE-2026-26418 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows rem... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now