2026 CVE Vulnerabilities
43,635 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58317 | MEDIUM | 6.3 | 0.3% | Jul 17, 2026 | Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Pr... |
| CVE-2026-41993 | MEDIUM | 6.7 | 0.1% | Jul 17, 2026 | Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a loc... |
| CVE-2026-21770 | MEDIUM | 6.5 | 0.1% | Jul 17, 2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker ... |
| CVE-2026-15759 | MEDIUM | 6.4 | 0.2% | Jul 17, 2026 | The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable t... |
| CVE-2026-15457 | MEDIUM | 4.9 | 0.8% | Jul 17, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversa... |
| CVE-2026-15349 | MEDIUM | 4.3 | 0.3% | Jul 17, 2026 | The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization b... |
| CVE-2026-15161 | MEDIUM | 6.4 | 0.2% | Jul 17, 2026 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and ... |
| CVE-2026-14503 | MEDIUM | 6.5 | 0.3% | Jul 17, 2026 | The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc... |
| CVE-2026-8616 | MEDIUM | 5.3 | 0.2% | Jul 17, 2026 | The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2026-15160 | MEDIUM | 4.3 | 0.5% | Jul 17, 2026 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl... |
| CVE-2026-15159 | MEDIUM | 4.3 | 0.2% | Jul 17, 2026 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up... |
| CVE-2026-11324 | MEDIUM | 6.1 | 0.3% | Jul 17, 2026 | The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cros... |
| CVE-2026-62237 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and ... |
| CVE-2026-62236 | MEDIUM | 5.4 | 0.1% | Jul 17, 2026 | grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASec... |
| CVE-2026-62235 | MEDIUM | 6.3 | 0.2% | Jul 17, 2026 | Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that al... |
| CVE-2026-62225 | MEDIUM | 5.4 | 0.2% | Jul 17, 2026 | OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows l... |
| CVE-2026-62224 | MEDIUM | 5.4 | 0.2% | Jul 17, 2026 | OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mu... |
| CVE-2026-62221 | MEDIUM | 5.4 | 0.1% | Jul 17, 2026 | OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature... |
| CVE-2026-62220 | MEDIUM | 6.3 | 0.3% | Jul 17, 2026 | OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limit... |
| CVE-2026-62216 | MEDIUM | 5 | 0.2% | Jul 17, 2026 | OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or c... |
| CVE-2026-62214 | MEDIUM | 6.5 | 0.3% | Jul 17, 2026 | OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-t... |
| CVE-2026-62213 | MEDIUM | 6.5 | 0.3% | Jul 17, 2026 | OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower... |
| CVE-2026-62211 | MEDIUM | 5 | 0.1% | Jul 17, 2026 | OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature t... |
| CVE-2026-62210 | MEDIUM | 6.5 | 0.3% | Jul 17, 2026 | OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-rea... |
| CVE-2026-62208 | MEDIUM | 6.5 | 0.3% | Jul 17, 2026 | OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enab... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now