2026 CVE Vulnerabilities

55,551 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-25888HIGH8.8Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-25887HIGH7.2Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-29046HIGH8.2TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header...
CVE-2026-29041HIGH8.8Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote co...
CVE-2026-28502HIGH8.8WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulner...
CVE-2026-3613HIGH7.3A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the ...
CVE-2026-3612HIGH7.3A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/...
CVE-2026-28727HIGH7.8Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber P...
CVE-2026-28722HIGH7.3Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec...
CVE-2026-28721HIGH7.3Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec...
CVE-2026-28718HIGH7.5Denial of service due to insufficient input validation in authentication logging. The following products are affected: A...
CVE-2026-28713HIGH7.1Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyb...
CVE-2026-27778HIGH8.7The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc...
CVE-2026-24912HIGH8.6The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ...
CVE-2026-29613HIGH8.2OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in whi...
CVE-2026-29612HIGH7.5OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget...
CVE-2026-29611HIGH8.2OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be inst...
CVE-2026-29610HIGH8.8OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintend...
CVE-2026-29609HIGH8.7OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the fetchWithGuard function that alloc...
CVE-2026-28485HIGH7.8OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control...
CVE-2026-28482HIGH8.4OpenClaw versions prior to 2026.2.12 construct transcript file paths using unsanitized sessionId parameters and sessionF...
CVE-2026-28481HIGH7.5OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS...
CVE-2026-28478HIGH8.7OpenClaw versions prior to 2026.2.13 contain a denial of service vulnerability in webhook handlers that buffer request b...
CVE-2026-28477HIGH7.1OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login f...
CVE-2026-28473HIGH8.1OpenClaw versions prior to 2026.2.2 contain an authorization bypass vulnerability where clients with operator.write scop...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now