2026 CVE Vulnerabilities

63,637 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33384MEDIUM4.8QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same...
CVE-2026-32906MEDIUM4.3OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-autho...
CVE-2026-32905HIGH8.7OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows no...
CVE-2026-10101MEDIUM6.3ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pul...
CVE-2026-10099MEDIUM5.1XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_s...
CVE-2026-10069HIGH8.7A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of the file usr/sbin/m...
CVE-2026-10068HIGH7.3A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of...
CVE-2026-10067HIGH8.8A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The mani...
CVE-2026-10066HIGH8.8A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the ...
CVE-2026-10065HIGH8.8A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file ...
CVE-2026-10064CRITICAL9.8A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file ...
CVE-2026-4290CRITICAL9.1The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-gui...
CVE-2026-45609MEDIUM6.5mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mc...
CVE-2026-41159MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ...
CVE-2026-41150MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ...
CVE-2026-39292HIGH7.3Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder...
CVE-2026-10063CRITICAL9.8A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the fil...
CVE-2026-10062CRITICAL9.8A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRou...
CVE-2026-10042CRITICAL9.8manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deseri...
CVE-2026-49325MEDIUM4.6Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 ...
CVE-2026-49318LOW2.4Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m...
CVE-2026-49317LOW2.4Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m...
CVE-2026-49316MEDIUM4.6Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allow...
CVE-2026-47696MEDIUM4.3WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits t...
CVE-2026-47694MEDIUM5.4WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now