2026 CVE Vulnerabilities

48,008 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-47745MEDIUM6.5Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carrie...
CVE-2026-47742MEDIUM6.5Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (E...
CVE-2026-47741MEDIUM5.9Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the ...
CVE-2026-46344MEDIUM5.3liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prio...
CVE-2026-44652MEDIUM6.9SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-44651MEDIUM6.9SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-44611MEDIUM5.9Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is su...
CVE-2026-44518MEDIUM5.3liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prio...
CVE-2026-42951MEDIUM5.9An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes accoun...
CVE-2026-40425MEDIUM4.9The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive file...
CVE-2026-45660MEDIUM5.4Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image prox...
CVE-2026-45626MEDIUM6.3Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /enviro...
CVE-2026-45577MEDIUM6.9Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public...
CVE-2026-43917MEDIUM5.3Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and earlier, the protectedProcedure middleware ...
CVE-2026-10070MEDIUM5.1A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of...
CVE-2026-39229MEDIUM6.5Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated atta...
CVE-2026-36324MEDIUM6.1SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of use...
CVE-2026-35673MEDIUM6.5OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows re...
CVE-2026-34507MEDIUM5.4OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated sende...
CVE-2026-33384MEDIUM4.8QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same...
CVE-2026-32906MEDIUM4.3OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-autho...
CVE-2026-10101MEDIUM6.3ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pul...
CVE-2026-10099MEDIUM5.1XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_s...
CVE-2026-45609MEDIUM6.5mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mc...
CVE-2026-41159MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now