2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-19009HIGH7.3A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core...
CVE-2026-19008MEDIUM6.3A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape...
CVE-2026-18915MEDIUM5Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research...
CVE-2026-18649HIGH7.5A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements d...
CVE-2026-18597HIGH8.5The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is re...
CVE-2026-0637MEDIUM4.4When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these propert...
CVE-2026-19007MEDIUM6.3A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedEle...
CVE-2026-19006MEDIUM6.3A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tool...
CVE-2026-19005MEDIUM6.3A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file s...
CVE-2026-18967HIGH8.1A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured a...
CVE-2026-18510HIGH7.2The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross...
CVE-2026-18400MEDIUM6.4The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Store...
CVE-2026-18395MEDIUM5.4The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before o...
CVE-2026-18050HIGH7.5The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves tem...
CVE-2026-16954MEDIUM6.5The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admi...
CVE-2026-16734HIGH7.5The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe p...
CVE-2026-16537MEDIUM5.4The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputtin...
CVE-2026-16290MEDIUM5.3The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member...
CVE-2026-16268HIGH8.2The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetchi...
CVE-2026-16065MEDIUM6.5The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV fil...
CVE-2026-16054CRITICAL9.1The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated us...
CVE-2026-14829HIGH8.2The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not pr...
CVE-2026-14547MEDIUM5.3The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict t...
CVE-2026-14314MEDIUM5.3The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment bel...
CVE-2026-14313MEDIUM5.3PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now