2026 CVE Vulnerabilities

45,453 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-48613MEDIUM5.9SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field dat...
CVE-2026-20746MEDIUM6.3Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust j...
CVE-2026-9125MEDIUM6.4The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the ...
CVE-2026-49482MEDIUM4.3ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an imprope...
CVE-2026-47238MEDIUM6.5ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can e...
CVE-2026-45173MEDIUM6.5Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validatio...
CVE-2026-12033MEDIUM5.3Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromise...
CVE-2026-12026MEDIUM6.5Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compr...
CVE-2026-12025MEDIUM5.3Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker...
CVE-2026-12024MEDIUM6.5Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker to bypass...
CVE-2026-12015MEDIUM5.3Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the re...
CVE-2026-53818MEDIUM6.9OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-own...
CVE-2026-53809MEDIUM4.8OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using pr...
CVE-2026-53808MEDIUM6.5OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows a...
CVE-2026-53781MEDIUM5.3Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhausti...
CVE-2026-49949MEDIUM6CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercep...
CVE-2026-45802MEDIUM6FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as template...
CVE-2026-53702MEDIUM6.5A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buf...
CVE-2026-53701MEDIUM6.5An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad....
CVE-2026-47250MEDIUM6.1mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the ...
CVE-2026-47177MEDIUM5.7Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a use...
CVE-2026-47176MEDIUM5.7Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a use...
CVE-2026-47173MEDIUM6.3Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a nor...
CVE-2026-47167MEDIUM5.3Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:s...
CVE-2026-47157MEDIUM6.5aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted server-supplied signup ch...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now