2026 CVE Vulnerabilities

56,998 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15620MEDIUM6.3A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the function tools.webFetch of ...
CVE-2026-0487HIGH8.4SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location...
CVE-2026-15619MEDIUM6.3A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the function web_fetch of the fi...
CVE-2026-15618MEDIUM6.3A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. The affected element is the function guardExecComma...
CVE-2026-58489MEDIUM6.8HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export ...
CVE-2026-58486HIGH8.3HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was ...
CVE-2026-58102CRITICAL9.1Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID...
CVE-2026-58101HIGH7.5Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2...
CVE-2026-57856HIGH8.8Cockpit CMS contains a path traversal vulnerability in the Bucket file storage API (/system/buckets/api). The api() meth...
CVE-2026-57855HIGH8.8Cockpit CMS contains a missing authorization vulnerability in the Bucket file storage API (/system/buckets/api). The api...
CVE-2026-15607MEDIUM4.3A vulnerability was detected in tanstack db up to 0.6.8. Affected by this vulnerability is the function select of the fi...
CVE-2026-15605LOW3.1A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download...
CVE-2026-62328HIGH8.79Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attack...
CVE-2026-62327CRITICAL9.39Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attac...
CVE-2026-62242HIGH8.6Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated a...
CVE-2026-62240HIGH8.3CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one...
CVE-2026-62239MEDIUM6.6FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, contains a symlink attack vulnerability in the download_and...
CVE-2026-62200HIGH8.8OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport t...
CVE-2026-62199HIGH8.8OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup va...
CVE-2026-62198MEDIUM5.4OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allo...
CVE-2026-62197HIGH8.5OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket ...
CVE-2026-62196HIGH8.3OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can s...
CVE-2026-62195HIGH8.7OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature th...
CVE-2026-62194HIGH8.8OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that...
CVE-2026-62193MEDIUM6.5OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now