2026 CVE Vulnerabilities

43,583 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-16085MEDIUM5.3A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of...
CVE-2026-16083MEDIUM5.5A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of th...
CVE-2026-16082MEDIUM5.3A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun ...
CVE-2026-16081MEDIUM4.3A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file w...
CVE-2026-16077MEDIUM5.3A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. Impacted is the function _normalize_rw_path of the file a...
CVE-2026-16076MEDIUM6.3A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_se...
CVE-2026-9734MEDIUM4.3The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2026-16075MEDIUM4.3A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat...
CVE-2026-57980MEDIUM5.4Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attac...
CVE-2026-48049MEDIUM5.3@hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static file...
CVE-2026-48022MEDIUM6.5@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie,...
CVE-2026-44979MEDIUM6.3@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname,...
CVE-2026-54497MEDIUM6.8view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4...
CVE-2026-54490MEDIUM6.3websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library is used with the pe...
CVE-2026-54243MEDIUM6.1Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission valu...
CVE-2026-54242MEDIUM4.9Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image prox...
CVE-2026-54163MEDIUM4.7secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds th...
CVE-2026-49977MEDIUM4.3tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on...
CVE-2026-45785MEDIUM6.2OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Sto...
CVE-2026-16074MEDIUM6.3A vulnerability was detected in AstrBotDevs AstrBot up to 4.25.2. This affects the function update_plugin/update_all_plu...
CVE-2026-8861MEDIUM5.3IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error messag...
CVE-2026-7771MEDIUM5.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted stat...
CVE-2026-7754MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure defa...
CVE-2026-7364MEDIUM6.1IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident...
CVE-2026-60137MEDIUM5.9WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now