2026 CVE Vulnerabilities
62,186 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32906 | MEDIUM | 4.3 | 0.2% | May 29, 2026 | OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-autho... |
| CVE-2026-32905 | HIGH | 8.7 | 0.2% | May 29, 2026 | OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows no... |
| CVE-2026-10101 | MEDIUM | 6.3 | 0.2% | May 29, 2026 | ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pul... |
| CVE-2026-10099 | MEDIUM | 5.1 | 0.1% | May 29, 2026 | XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_s... |
| CVE-2026-10069 | HIGH | 8.7 | 0.4% | May 29, 2026 | A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of the file usr/sbin/m... |
| CVE-2026-10068 | HIGH | 7.3 | 0.3% | May 29, 2026 | A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of... |
| CVE-2026-10067 | HIGH | 8.8 | 0.4% | May 29, 2026 | A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The mani... |
| CVE-2026-10066 | HIGH | 8.8 | 0.4% | May 29, 2026 | A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the ... |
| CVE-2026-10065 | HIGH | 8.8 | 0.4% | May 29, 2026 | A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file ... |
| CVE-2026-10064 | CRITICAL | 9.8 | 0.4% | May 29, 2026 | A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file ... |
| CVE-2026-4290 | CRITICAL | 9.1 | 0.3% | May 29, 2026 | The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-gui... |
| CVE-2026-45609 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mc... |
| CVE-2026-41159 | MEDIUM | 5.3 | 0.4% | May 29, 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ... |
| CVE-2026-41150 | MEDIUM | 5.3 | 0.4% | May 29, 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ... |
| CVE-2026-39292 | HIGH | 7.3 | 0.5% | May 29, 2026 | Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder... |
| CVE-2026-10063 | CRITICAL | 9.8 | 0.9% | May 29, 2026 | A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the fil... |
| CVE-2026-10062 | CRITICAL | 9.8 | 0.8% | May 29, 2026 | A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRou... |
| CVE-2026-10042 | CRITICAL | 9.8 | 0.6% | May 29, 2026 | manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deseri... |
| CVE-2026-49325 | MEDIUM | 4.6 | 0.2% | May 29, 2026 | Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 ... |
| CVE-2026-49318 | LOW | 2.4 | 0.1% | May 29, 2026 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m... |
| CVE-2026-49317 | LOW | 2.4 | 0.1% | May 29, 2026 | Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m... |
| CVE-2026-49316 | MEDIUM | 4.6 | 0.2% | May 29, 2026 | Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allow... |
| CVE-2026-47696 | MEDIUM | 4.3 | 0.1% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits t... |
| CVE-2026-47694 | MEDIUM | 5.4 | 0.2% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input a... |
| CVE-2026-46510 | HIGH | 8.2 | 0.3% | May 29, 2026 | form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now