2026 CVE Vulnerabilities

68,107 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27093HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27091MEDIUM6.3Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured Access...
CVE-2026-28073HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tips and Tricks HQ...
CVE-2026-28070MEDIUM5.3Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting Incorrectly Configured Access Con...
CVE-2026-28044MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket...
CVE-2026-27542CRITICAL9.8Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wh...
CVE-2026-27540CRITICAL9Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Captu...
CVE-2026-27413CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile...
CVE-2026-27397MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro ...
CVE-2026-27096HIGH8.1Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows O...
CVE-2026-1238HIGH7.2The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) para...
CVE-2026-1276MEDIUM5.4IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows a...
CVE-2026-32000HIGH7.1OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution t...
CVE-2026-31999HIGH7.8OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in ...
CVE-2026-31998HIGH8.6OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plu...
CVE-2026-31997MEDIUM6.7OpenClaw versions prior to 2026.3.1 fail to pin executable identity for non-path-like argv[0] tokens in system.run appro...
CVE-2026-31996MEDIUM4.4OpenClaw versions prior to 2026.2.19 tools.exec.safeBins contains an input validation bypass vulnerability that allows a...
CVE-2026-31995HIGH7OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Wind...
CVE-2026-31994HIGH7.8OpenClaw versions prior to 2026.2.19 contain a local command injection vulnerability in Windows scheduled task script ge...
CVE-2026-31993MEDIUM6.4OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion app that...
CVE-2026-31992HIGH8.8OpenClaw versions prior to 2026.2.23 contain an allowlist bypass vulnerability in system.run guardrails that allows auth...
CVE-2026-31991MEDIUM4.6OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where Signal group allowlist policy i...
CVE-2026-31990HIGH7.1OpenClaw versions prior to 2026.3.2 contain a vulnerability in the stageSandboxMedia function in which it fails to valid...
CVE-2026-31989MEDIUM6.3OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation redirect ...
CVE-2026-29608MEDIUM6.7OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewriting ch...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now