2026 CVE Vulnerabilities

43,635 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-58317MEDIUM6.3Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Pr...
CVE-2026-41993MEDIUM6.7Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a loc...
CVE-2026-21770MEDIUM6.5HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker ...
CVE-2026-15759MEDIUM6.4The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable t...
CVE-2026-15457MEDIUM4.9The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversa...
CVE-2026-15349MEDIUM4.3The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization b...
CVE-2026-15161MEDIUM6.4The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and ...
CVE-2026-14503MEDIUM6.5The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc...
CVE-2026-8616MEDIUM5.3The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2026-15160MEDIUM4.3The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl...
CVE-2026-15159MEDIUM4.3The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up...
CVE-2026-11324MEDIUM6.1The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cros...
CVE-2026-62237MEDIUM6.5Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and ...
CVE-2026-62236MEDIUM5.4grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASec...
CVE-2026-62235MEDIUM6.3Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that al...
CVE-2026-62225MEDIUM5.4OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows l...
CVE-2026-62224MEDIUM5.4OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mu...
CVE-2026-62221MEDIUM5.4OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature...
CVE-2026-62220MEDIUM6.3OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limit...
CVE-2026-62216MEDIUM5OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or c...
CVE-2026-62214MEDIUM6.5OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-t...
CVE-2026-62213MEDIUM6.5OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower...
CVE-2026-62211MEDIUM5OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature t...
CVE-2026-62210MEDIUM6.5OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-rea...
CVE-2026-62208MEDIUM6.5OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enab...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now