2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-62211MEDIUM5OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature t...
CVE-2026-62210MEDIUM6.5OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-rea...
CVE-2026-62209HIGH8.1OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch...
CVE-2026-62208MEDIUM6.5OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enab...
CVE-2026-62207HIGH8.8OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reac...
CVE-2026-62206HIGH7.1OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affect...
CVE-2026-62205HIGH7.1OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message...
CVE-2026-62203HIGH8.8OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to pro...
CVE-2026-62202HIGH8.8OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allow...
CVE-2026-62201HIGH7.7OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows l...
CVE-2026-44251MEDIUM6.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and abov...
CVE-2026-40106HIGH7.8Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above p...
CVE-2026-2594MEDIUM6.4The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi...
CVE-2026-14956CRITICAL9.8The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6...
CVE-2026-54340HIGH7.5h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state am...
CVE-2026-39359HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through ...
CVE-2026-34150HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and abov...
CVE-2026-33754MEDIUM6.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and abov...
CVE-2026-33434HIGH7.1Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and abov...
CVE-2026-44453HIGH7.5h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Deni...
CVE-2026-44452MEDIUM5.9h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientH...
CVE-2026-44436HIGH7.5Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b...
CVE-2026-44435HIGH7.5Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 93...
CVE-2026-44434MEDIUM5.3Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dc...
CVE-2026-44433HIGH7.5Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now