2026 CVE Vulnerabilities
56,998 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62192 | HIGH | 8.1 | 0.2% | Jul 13, 2026 | OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that a... |
| CVE-2026-62191 | HIGH | 7.1 | 0.2% | Jul 13, 2026 | OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling th... |
| CVE-2026-62190 | HIGH | 8.8 | 0.3% | Jul 13, 2026 | OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-t... |
| CVE-2026-62189 | HIGH | 7.6 | 0.3% | Jul 13, 2026 | OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower... |
| CVE-2026-62188 | HIGH | 8.6 | 0.2% | Jul 13, 2026 | OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Fe... |
| CVE-2026-62187 | HIGH | 8.6 | 0.2% | Jul 13, 2026 | OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A low... |
| CVE-2026-62186 | HIGH | 7.6 | 0.2% | Jul 13, 2026 | OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model override... |
| CVE-2026-62185 | HIGH | 8.6 | 0.3% | Jul 13, 2026 | Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access r... |
| CVE-2026-62184 | HIGH | 8.7 | 0.4% | Jul 13, 2026 | luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log ... |
| CVE-2026-61458 | HIGH | 8.7 | 0.3% | Jul 13, 2026 | PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-... |
| CVE-2026-59801 | CRITICAL | 9.8 | 0.5% | Jul 13, 2026 | 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact... |
| CVE-2026-58500 | HIGH | 8.2 | 0.4% | Jul 13, 2026 | MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on Android and iOS. In... |
| CVE-2026-58488 | MEDIUM | 6.9 | 0.3% | Jul 13, 2026 | HedgeDoc is an open source, real-time, collaborative, markdown notes application. Versions prior to 1.11.0 allowed attac... |
| CVE-2026-58487 | MEDIUM | 5.1 | 0.4% | Jul 13, 2026 | HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, due to unsafe... |
| CVE-2026-58411 | HIGH | 7 | 0.3% | Jul 13, 2026 | ChurchCRM is an open-source church management system. Prior to version 7.4.0, Cross-Site Scripting (XSS) vulnerabilities... |
| CVE-2026-56877 | MEDIUM | 6.3 | 0.4% | Jul 13, 2026 | The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplie... |
| CVE-2026-52533 | CRITICAL | 9.8 | 0.4% | Jul 13, 2026 | An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component... |
| CVE-2026-51821 | CRITICAL | 9.8 | 0.5% | Jul 13, 2026 | SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitra... |
| CVE-2026-51541 | CRITICAL | 9.1 | 0.4% | Jul 13, 2026 | OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit re... |
| CVE-2026-51540 | CRITICAL | 9.8 | 0.4% | Jul 13, 2026 | OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer... |
| CVE-2026-51539 | HIGH | 7.5 | 0.3% | Jul 13, 2026 | A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issu... |
| CVE-2026-51538 | CRITICAL | 9.1 | 0.4% | Jul 13, 2026 | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of en... |
| CVE-2026-51537 | CRITICAL | 9.1 | 0.4% | Jul 13, 2026 | EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpe... |
| CVE-2026-51536 | CRITICAL | 9.1 | 0.5% | Jul 13, 2026 | In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length para... |
| CVE-2026-39042 | HIGH | 7.5 | 0.4% | Jul 13, 2026 | An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now