2026 CVE Vulnerabilities

63,163 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33386LOW2.3QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malici...
CVE-2026-33384MEDIUM4.8QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same...
CVE-2026-32906MEDIUM4.3OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-autho...
CVE-2026-32905HIGH8.7OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows no...
CVE-2026-10101MEDIUM6.3ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pul...
CVE-2026-10099MEDIUM5.1XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_s...
CVE-2026-10069HIGH8.7A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of the file usr/sbin/m...
CVE-2026-10068HIGH7.3A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of...
CVE-2026-10067HIGH8.8A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The mani...
CVE-2026-10066HIGH8.8A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the ...
CVE-2026-10065HIGH8.8A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file ...
CVE-2026-10064CRITICAL9.8A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file ...
CVE-2026-4290CRITICAL9.1The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-gui...
CVE-2026-45609MEDIUM6.5mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mc...
CVE-2026-41159MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ...
CVE-2026-41150MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ...
CVE-2026-39292HIGH7.3Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder...
CVE-2026-10063CRITICAL9.8A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the fil...
CVE-2026-10062CRITICAL9.8A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRou...
CVE-2026-10042CRITICAL9.8manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deseri...
CVE-2026-49325MEDIUM4.6Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 ...
CVE-2026-49318LOW2.4Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m...
CVE-2026-49317LOW2.4Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m...
CVE-2026-49316MEDIUM4.6Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allow...
CVE-2026-47696MEDIUM4.3WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now