2026 CVE Vulnerabilities

56,007 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-26959HIGH7.8ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below fail to validate the integrity or authentic...
CVE-2026-26325HIGH7.2OpenClaw is a personal AI assistant. Prior to version 2026.2.14, a mismatch between `rawCommand` and `command[]` in the ...
CVE-2026-26324HIGH7.5OpenClaw is a personal AI assistant. Prior to version 2026.2.14, OpenClaw's SSRF protection could be bypassed using full...
CVE-2026-26323HIGH8.8OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev ...
CVE-2026-26322HIGH7.6OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Gateway tool accepted a tool-supplied `gat...
CVE-2026-26321HIGH7.5OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed `sendM...
CVE-2026-26319HIGH7.5OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx ...
CVE-2026-21535HIGH7.5Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
CVE-2026-26317HIGH7.1OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin ...
CVE-2026-26316HIGH7.5OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept w...
CVE-2026-26315HIGH7.5go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through...
CVE-2026-26314HIGH7.5go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulne...
CVE-2026-26275HIGH7.5httpsig-hyper is a hyper extension for http message signatures. An issue was discovered in `httpsig-hyper` prior to vers...
CVE-2026-27343HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27114HIGH7.5NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOf...
CVE-2026-26313HIGH7.5go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an atta...
CVE-2026-26286HIGH8.5SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-26318HIGH8.8systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command...
CVE-2026-26280HIGH7.8systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection v...
CVE-2026-26278HIGH7.5fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li...
CVE-2026-26267HIGH7.5soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` ma...
CVE-2026-26205HIGH7.1opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability i...
CVE-2026-26202HIGH7.5Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user c...
CVE-2026-26201HIGH7.5emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 3.21.2, multiple shared maps are access...
CVE-2026-26200HIGH7.8HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now