2026 CVE Vulnerabilities

53,709 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-28464HIGH7.5OpenClaw versions prior to 2026.2.12 use non-constant-time string comparison for hook token validation, allowing attacke...
CVE-2026-28459HIGH8.1OpenClaw versions prior to 2026.2.12 fail to validate the sessionFile path parameter, allowing authenticated gateway cli...
CVE-2026-28457HIGH7.9OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in sandbox skill mirroring (must be enabled)...
CVE-2026-28456HIGH8.6OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently c...
CVE-2026-28450HIGH8.2OpenClaw versions prior to 2026.2.12 with the optional Nostr plugin enabled expose unauthenticated HTTP endpoints at /ap...
CVE-2026-29188HIGH8.1File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ...
CVE-2026-29081HIGH8.8Frappe is a full-stack web application framework. Prior to versions 14.100.1 and 15.100.0, an endpoint was vulnerable to...
CVE-2026-29077HIGH7.1Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation wh...
CVE-2026-28442HIGH8.5ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, u...
CVE-2026-28436HIGH7.2Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted ...
CVE-2026-28410HIGH8.1The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to ve...
CVE-2026-28790HIGH7.5OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an ...
CVE-2026-28789HIGH7.5OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated ...
CVE-2026-28342HIGH7.5OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash AP...
CVE-2026-28277HIGH7.2LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ...
CVE-2026-3459HIGH8.1The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due...
CVE-2026-3047HIGH8.8A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is config...
CVE-2026-3009HIGH8.1A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an...
CVE-2026-29054HIGH7.5Traefik is an HTTP reverse proxy and load balancer. From version 2.11.9 to 2.11.37 and from version 3.1.3 to 3.6.8, ther...
CVE-2026-28287HIGH8.8FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, ...
CVE-2026-28284HIGH8.8FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several aut...
CVE-2026-28210HIGH8.8FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnera...
CVE-2026-28209HIGH7.2FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, ...
CVE-2026-26999HIGH7.5Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerabil...
CVE-2026-26418HIGH7.5Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows rem...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now