2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-64640MEDIUM6.5Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenti...
CVE-2026-19022MEDIUM6.3A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initialize_repo of the fi...
CVE-2026-19020MEDIUM6.3A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unkn...
CVE-2026-19019MEDIUM4.8A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_...
CVE-2026-19011MEDIUM5.5A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packa...
CVE-2026-19008MEDIUM6.3A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape...
CVE-2026-18915MEDIUM5Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research...
CVE-2026-0637MEDIUM4.4When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these propert...
CVE-2026-19007MEDIUM6.3A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedEle...
CVE-2026-19006MEDIUM6.3A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tool...
CVE-2026-19005MEDIUM6.3A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file s...
CVE-2026-18400MEDIUM6.4The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Store...
CVE-2026-18395MEDIUM5.4The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before o...
CVE-2026-16954MEDIUM6.5The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admi...
CVE-2026-16537MEDIUM5.4The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputtin...
CVE-2026-16290MEDIUM5.3The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member...
CVE-2026-16065MEDIUM6.5The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV fil...
CVE-2026-14547MEDIUM5.3The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict t...
CVE-2026-14314MEDIUM5.3The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment bel...
CVE-2026-14313MEDIUM5.3PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-...
CVE-2026-14240MEDIUM5.3The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its pub...
CVE-2026-14204MEDIUM6.5The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, all...
CVE-2026-13703MEDIUM5.4The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated...
CVE-2026-11588MEDIUM6.1The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API route...
CVE-2026-18998MEDIUM6.3A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now