2026 CVE Vulnerabilities

69,542 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30901HIGH7.8Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduc...
CVE-2026-30900HIGH7.8Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated...
CVE-2026-3904MEDIUM6.2Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library ...
CVE-2026-3496HIGH7.5The JetBooking plugin for WordPress is vulnerable to SQL Injection via the 'check_in_date' parameter in all versions up ...
CVE-2026-32063HIGH7.8OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generati...
CVE-2026-32062HIGH8.7OpenClaw versions 2026.2.21-2 up to, but not including, 2026.2.22, and @openclaw/voice-call versions 2026.2.21 up to, bu...
CVE-2026-32061MEDIUM6.7OpenClaw versions prior to 2026.2.17 contain a path traversal vulnerability in the $include directive resolution that al...
CVE-2026-32060HIGH8.8OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to writ...
CVE-2026-32059HIGH8.8OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly valida...
CVE-2026-3944CRITICAL9.8A vulnerability was determined in itsourcecode University Management System 1.0. This vulnerability affects unknown code...
CVE-2026-3943HIGH7.3A vulnerability was found in H3C ACG1000-AK230 up to 20260227. This affects an unknown part of the file /webui/?aaa_port...
CVE-2026-3178HIGH7.2The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' param...
CVE-2026-3805HIGH7.5When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already free...
CVE-2026-3784MEDIUM6.5curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses diffe...
CVE-2026-3783MEDIUM5.3When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl...
CVE-2026-1965MEDIUM6.5libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS r...
CVE-2026-3906MEDIUM4.3WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collab...
CVE-2026-3492MEDIUM6.4The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including...
CVE-2026-3231HIGH7.2The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2026-1993HIGH8.8The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in ver...
CVE-2026-1992HIGH8.8The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in ...
CVE-2026-1454HIGH7.2The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2026-3903MEDIUM4.3The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Cross-Site Request F...
CVE-2026-2918MEDIUM6.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up...
CVE-2026-2917MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now