2026 CVE Vulnerabilities

45,449 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-9629MEDIUM6.4The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up ...
CVE-2026-3297MEDIUM6.4The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2026-2470MEDIUM4.3The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorizatio...
CVE-2026-9134MEDIUM6.4The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcod...
CVE-2026-54231MEDIUM5.5A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script...
CVE-2026-12089MEDIUM4.9The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in v...
CVE-2026-11443MEDIUM4.6Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote at...
CVE-2026-11442MEDIUM6.5Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attacker...
CVE-2026-54398MEDIUM5.3An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions t...
CVE-2026-53867MEDIUM5.3Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remo...
CVE-2026-53839MEDIUM6.5OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching host...
CVE-2026-53837MEDIUM5.3OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to va...
CVE-2026-53835MEDIUM4.3OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that...
CVE-2026-53834MEDIUM6.5OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allow...
CVE-2026-53833MEDIUM6.5OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows auth...
CVE-2026-53830MEDIUM6.5OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and ...
CVE-2026-53827MEDIUM6.5OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-con...
CVE-2026-53826MEDIUM4.3OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spawning that exposes th...
CVE-2026-53824MEDIUM6.5OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to contin...
CVE-2026-53820MEDIUM6.9OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path t...
CVE-2026-53523MEDIUM6.8Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to be...
CVE-2026-53522MEDIUM6.5Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to be...
CVE-2026-53521MEDIUM6.4Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to b...
CVE-2026-53520MEDIUM6.5Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.14 to b...
CVE-2026-49397MEDIUM5.3Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 2.0.0 to be...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now