2026 CVE Vulnerabilities
69,542 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30901 | HIGH | 7.8 | 0.1% | Mar 11, 2026 | Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduc... |
| CVE-2026-30900 | HIGH | 7.8 | 0.1% | Mar 11, 2026 | Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated... |
| CVE-2026-3904 | MEDIUM | 6.2 | 0.1% | Mar 11, 2026 | Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library ... |
| CVE-2026-3496 | HIGH | 7.5 | 0.3% | Mar 11, 2026 | The JetBooking plugin for WordPress is vulnerable to SQL Injection via the 'check_in_date' parameter in all versions up ... |
| CVE-2026-32063 | HIGH | 7.8 | 1.1% | Mar 11, 2026 | OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generati... |
| CVE-2026-32062 | HIGH | 8.7 | 0.4% | Mar 11, 2026 | OpenClaw versions 2026.2.21-2 up to, but not including, 2026.2.22, and @openclaw/voice-call versions 2026.2.21 up to, bu... |
| CVE-2026-32061 | MEDIUM | 6.7 | 0.1% | Mar 11, 2026 | OpenClaw versions prior to 2026.2.17 contain a path traversal vulnerability in the $include directive resolution that al... |
| CVE-2026-32060 | HIGH | 8.8 | 0.7% | Mar 11, 2026 | OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to writ... |
| CVE-2026-32059 | HIGH | 8.8 | 0.4% | Mar 11, 2026 | OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly valida... |
| CVE-2026-3944 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | A vulnerability was determined in itsourcecode University Management System 1.0. This vulnerability affects unknown code... |
| CVE-2026-3943 | HIGH | 7.3 | 40.8% | Mar 11, 2026 | A vulnerability was found in H3C ACG1000-AK230 up to 20260227. This affects an unknown part of the file /webui/?aaa_port... |
| CVE-2026-3178 | HIGH | 7.2 | 0.3% | Mar 11, 2026 | The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' param... |
| CVE-2026-3805 | HIGH | 7.5 | 0.7% | Mar 11, 2026 | When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already free... |
| CVE-2026-3784 | MEDIUM | 6.5 | 0.4% | Mar 11, 2026 | curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses diffe... |
| CVE-2026-3783 | MEDIUM | 5.3 | 0.5% | Mar 11, 2026 | When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl... |
| CVE-2026-1965 | MEDIUM | 6.5 | 0.3% | Mar 11, 2026 | libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS r... |
| CVE-2026-3906 | MEDIUM | 4.3 | 0.3% | Mar 11, 2026 | WordPress core is vulnerable to unauthorized access in versions 6.9 through 6.9.1. The Notes feature (block-level collab... |
| CVE-2026-3492 | MEDIUM | 6.4 | 0.2% | Mar 11, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including... |
| CVE-2026-3231 | HIGH | 7.2 | 0.3% | Mar 11, 2026 | The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scr... |
| CVE-2026-1993 | HIGH | 8.8 | 0.4% | Mar 11, 2026 | The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in ver... |
| CVE-2026-1992 | HIGH | 8.8 | 0.6% | Mar 11, 2026 | The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in ... |
| CVE-2026-1454 | HIGH | 7.2 | 0.2% | Mar 11, 2026 | The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scr... |
| CVE-2026-3903 | MEDIUM | 4.3 | 0.1% | Mar 11, 2026 | The Modular DS: Monitor, update, and backup multiple websites plugin for WordPress is vulnerable to Cross-Site Request F... |
| CVE-2026-2918 | MEDIUM | 6.4 | 0.2% | Mar 11, 2026 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up... |
| CVE-2026-2917 | MEDIUM | 5.4 | 0.2% | Mar 11, 2026 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now