2026 CVE Vulnerabilities
56,998 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15620 | MEDIUM | 6.3 | 0.2% | Jul 14, 2026 | A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the function tools.webFetch of ... |
| CVE-2026-0487 | HIGH | 8.4 | 0.1% | Jul 14, 2026 | SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location... |
| CVE-2026-15619 | MEDIUM | 6.3 | 0.3% | Jul 14, 2026 | A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the function web_fetch of the fi... |
| CVE-2026-15618 | MEDIUM | 6.3 | 0.2% | Jul 14, 2026 | A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. The affected element is the function guardExecComma... |
| CVE-2026-58489 | MEDIUM | 6.8 | 0.1% | Jul 13, 2026 | HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export ... |
| CVE-2026-58486 | HIGH | 8.3 | 0.2% | Jul 13, 2026 | HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was ... |
| CVE-2026-58102 | CRITICAL | 9.1 | 0.2% | Jul 13, 2026 | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID... |
| CVE-2026-58101 | HIGH | 7.5 | 0.2% | Jul 13, 2026 | Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2... |
| CVE-2026-57856 | HIGH | 8.8 | 0.4% | Jul 13, 2026 | Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() meth... |
| CVE-2026-57855 | HIGH | 8.8 | 0.3% | Jul 13, 2026 | Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api... |
| CVE-2026-15607 | MEDIUM | 4.3 | 0.3% | Jul 13, 2026 | A vulnerability was detected in tanstack db up to 0.6.8. Affected by this vulnerability is the function select of the fi... |
| CVE-2026-15605 | LOW | 3.1 | 0.2% | Jul 13, 2026 | A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download... |
| CVE-2026-62328 | HIGH | 8.7 | 0.4% | Jul 13, 2026 | 9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attack... |
| CVE-2026-62327 | CRITICAL | 9.3 | 0.4% | Jul 13, 2026 | 9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attac... |
| CVE-2026-62242 | HIGH | 8.6 | 0.3% | Jul 13, 2026 | Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated a... |
| CVE-2026-62240 | HIGH | 8.3 | 0.3% | Jul 13, 2026 | CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one... |
| CVE-2026-62239 | MEDIUM | 6.6 | 0.1% | Jul 13, 2026 | FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and... |
| CVE-2026-62200 | HIGH | 8.8 | 0.3% | Jul 13, 2026 | OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport t... |
| CVE-2026-62199 | HIGH | 8.8 | 0.3% | Jul 13, 2026 | OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup va... |
| CVE-2026-62198 | MEDIUM | 5.4 | 0.2% | Jul 13, 2026 | OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allo... |
| CVE-2026-62197 | HIGH | 8.5 | 0.2% | Jul 13, 2026 | OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket ... |
| CVE-2026-62196 | HIGH | 8.3 | 0.4% | Jul 13, 2026 | OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can s... |
| CVE-2026-62195 | HIGH | 8.7 | 0.2% | Jul 13, 2026 | OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature th... |
| CVE-2026-62194 | HIGH | 8.8 | 0.3% | Jul 13, 2026 | OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that... |
| CVE-2026-62193 | MEDIUM | 6.5 | 0.2% | Jul 13, 2026 | OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the in... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now