2026 CVE Vulnerabilities

70,008 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28714MEDIUM4.8Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect...
CVE-2026-28713HIGH7.1Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyb...
CVE-2026-28712MEDIUM6.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec...
CVE-2026-28711MEDIUM6.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec...
CVE-2026-28710CRITICAL9.8Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: A...
CVE-2026-28709MEDIUM4.3Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cy...
CVE-2026-27778HIGH8.7The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc...
CVE-2026-27770MEDIUM6.9Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-24912HIGH8.6The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ...
CVE-2026-22552CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat...
CVE-2026-26125CRITICAL9.8Payment Orchestrator Service Elevation of Privilege Vulnerability
CVE-2026-26124MEDIUM6.7'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
CVE-2026-26122MEDIUM6.5Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose...
CVE-2026-23651MEDIUM6.7Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
CVE-2026-21536CRITICAL9.8Microsoft Devices Pricing Program Remote Code Execution Vulnerability
CVE-2026-3606MEDIUM5.5A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segme...
CVE-2026-2593MEDIUM6.4The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2026-29613HIGH8.2OpenClaw versions prior to 2026.2.12 contain a vulnerability in the BlueBubbles (optional plugin) webhook handler in whi...
CVE-2026-29612HIGH7.5OpenClaw versions prior to 2026.2.14 decode base64-backed media inputs into buffers before enforcing decoded-size budget...
CVE-2026-29611HIGH8.2OpenClaw versions prior to 2026.2.14 contain a local file inclusion vulnerability in BlueBubbles extension (must be inst...
CVE-2026-29610HIGH8.8OpenClaw versions prior to 2026.2.14 contain a command hijacking vulnerability that allows attackers to execute unintend...
CVE-2026-29609HIGH8.7OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the fetchWithGuard function that alloc...
CVE-2026-29606MEDIUM6.5OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that al...
CVE-2026-28486MEDIUM5.5OpenClaw versions 2026.1.16-2 prior to 2026.2.14 contain a path traversal vulnerability in archive extraction during ins...
CVE-2026-28485HIGH7.8OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now