2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64640 | MEDIUM | 6.5 | 0.3% | Aug 6, 2026 | Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenti... |
| CVE-2026-19022 | MEDIUM | 6.3 | 1.3% | Aug 6, 2026 | A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initialize_repo of the fi... |
| CVE-2026-19020 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2026-19019 | MEDIUM | 4.8 | 0.3% | Aug 6, 2026 | A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_... |
| CVE-2026-19011 | MEDIUM | 5.5 | 0.4% | Aug 6, 2026 | A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packa... |
| CVE-2026-19008 | MEDIUM | 6.3 | 0.3% | Aug 6, 2026 | A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape... |
| CVE-2026-18915 | MEDIUM | 5 | — | Aug 6, 2026 | Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research... |
| CVE-2026-0637 | MEDIUM | 4.4 | 0.1% | Aug 6, 2026 | When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these propert... |
| CVE-2026-19007 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedEle... |
| CVE-2026-19006 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tool... |
| CVE-2026-19005 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file s... |
| CVE-2026-18400 | MEDIUM | 6.4 | 0.3% | Aug 6, 2026 | The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Store... |
| CVE-2026-18395 | MEDIUM | 5.4 | — | Aug 6, 2026 | The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before o... |
| CVE-2026-16954 | MEDIUM | 6.5 | 0.2% | Aug 6, 2026 | The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admi... |
| CVE-2026-16537 | MEDIUM | 5.4 | — | Aug 6, 2026 | The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputtin... |
| CVE-2026-16290 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member... |
| CVE-2026-16065 | MEDIUM | 6.5 | — | Aug 6, 2026 | The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV fil... |
| CVE-2026-14547 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict t... |
| CVE-2026-14314 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment bel... |
| CVE-2026-14313 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-... |
| CVE-2026-14240 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its pub... |
| CVE-2026-14204 | MEDIUM | 6.5 | 0.1% | Aug 6, 2026 | The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, all... |
| CVE-2026-13703 | MEDIUM | 5.4 | 0.1% | Aug 6, 2026 | The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated... |
| CVE-2026-11588 | MEDIUM | 6.1 | — | Aug 6, 2026 | The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API route... |
| CVE-2026-18998 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now