2026 CVE Vulnerabilities

56,034 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-2435HIGH8.8Tanium addressed a SQL injection vulnerability in Asset.
CVE-2026-27001HIGH7.8OpenClaw is a personal AI assistant. Prior to version 2026.2.15, OpenClaw embedded the current working directory (worksp...
CVE-2026-26959HIGH7.8ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below fail to validate the integrity or authentic...
CVE-2026-26325HIGH7.2OpenClaw is a personal AI assistant. Prior to version 2026.2.14, a mismatch between `rawCommand` and `command[]` in the ...
CVE-2026-26324HIGH7.5OpenClaw is a personal AI assistant. Prior to version 2026.2.14, OpenClaw's SSRF protection could be bypassed using full...
CVE-2026-26323HIGH8.8OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev ...
CVE-2026-26322HIGH7.6OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Gateway tool accepted a tool-supplied `gat...
CVE-2026-26321HIGH7.5OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed `sendM...
CVE-2026-26319HIGH7.5OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx ...
CVE-2026-21535HIGH7.5Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
CVE-2026-26317HIGH7.1OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin ...
CVE-2026-26316HIGH7.5OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept w...
CVE-2026-26315HIGH7.5go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through...
CVE-2026-26314HIGH7.5go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulne...
CVE-2026-26275HIGH7.5httpsig-hyper is a hyper extension for http message signatures. An issue was discovered in `httpsig-hyper` prior to vers...
CVE-2026-27343HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27114HIGH7.5NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOf...
CVE-2026-26313HIGH7.5go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an atta...
CVE-2026-26286HIGH8.5SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-26318HIGH8.8systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command...
CVE-2026-26280HIGH7.8systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection v...
CVE-2026-26278HIGH7.5fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li...
CVE-2026-26267HIGH7.5soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` ma...
CVE-2026-26205HIGH7.1opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability i...
CVE-2026-26202HIGH7.5Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now