2026 CVE Vulnerabilities
67,653 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28044 | MEDIUM | 5.9 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket... |
| CVE-2026-27542 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wh... |
| CVE-2026-27540 | CRITICAL | 9 | 0.5% | Mar 19, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Captu... |
| CVE-2026-27413 | CRITICAL | 9.3 | 0.4% | Mar 19, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile... |
| CVE-2026-27397 | MEDIUM | 6.5 | 0.2% | Mar 19, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro ... |
| CVE-2026-27096 | HIGH | 8.1 | 0.3% | Mar 19, 2026 | Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows O... |
| CVE-2026-1238 | HIGH | 7.2 | 0.3% | Mar 19, 2026 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) para... |
| CVE-2026-1276 | MEDIUM | 5.4 | 0.1% | Mar 19, 2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows a... |
| CVE-2026-32000 | HIGH | 7.1 | 0.6% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution t... |
| CVE-2026-31999 | HIGH | 7.8 | 0.2% | Mar 19, 2026 | OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in ... |
| CVE-2026-31998 | HIGH | 8.6 | 0.3% | Mar 19, 2026 | OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plu... |
| CVE-2026-31997 | MEDIUM | 6.7 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.1 fail to pin executable identity for non-path-like argv[0] tokens in system.run appro... |
| CVE-2026-31996 | MEDIUM | 4.4 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.19 tools.exec.safeBins contains an input validation bypass vulnerability that allows a... |
| CVE-2026-31995 | HIGH | 7 | 0.5% | Mar 19, 2026 | OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Wind... |
| CVE-2026-31994 | HIGH | 7.8 | 0.6% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.19 contain a local command injection vulnerability in Windows scheduled task script ge... |
| CVE-2026-31993 | MEDIUM | 6.4 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion app that... |
| CVE-2026-31992 | HIGH | 8.8 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allows auth... |
| CVE-2026-31991 | MEDIUM | 4.6 | 0.2% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where Signal group allowlist policy i... |
| CVE-2026-31990 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to valid... |
| CVE-2026-31989 | MEDIUM | 6.3 | 0.2% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation redirect ... |
| CVE-2026-29608 | MEDIUM | 6.7 | 0.1% | Mar 19, 2026 | OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewriting ch... |
| CVE-2026-29607 | HIGH | 7.1 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persistence t... |
| CVE-2026-28461 | HIGH | 8.7 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.3.1 contain an unbounded memory growth vulnerability in the Zalo webhook endpoint that a... |
| CVE-2026-28460 | HIGH | 7.1 | 0.4% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers to ex... |
| CVE-2026-28449 | MEDIUM | 6.5 | 0.3% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now