2026 CVE Vulnerabilities

65,537 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100612HIGH7.2Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.sso_providers table....
CVE-2026-100611MEDIUM6.5Capgo (capgo.app backend, versions ≤ 12.261.0) improperly restricts which roles the apikey_manager organization role may...
CVE-2026-100610HIGH7.5Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permis...
CVE-2026-100609MEDIUM6.8Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on ...
CVE-2026-100608HIGH8.3Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode w...
CVE-2026-100607HIGH7.7Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or subject identifi...
CVE-2026-100606HIGH7.7Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login pat...
CVE-2026-100605HIGH7.1Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API k...
CVE-2026-100604MEDIUM5.4ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an orga...
CVE-2026-100603MEDIUM5.4ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordina...
CVE-2026-100602MEDIUM6.5ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. ...
CVE-2026-100601MEDIUM5.3ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profil...
CVE-2026-100600MEDIUM5.3ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identit...
CVE-2026-100315HIGH7.3A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. ...
CVE-2026-100314HIGH7.3A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db...
CVE-2026-100313MEDIUM4.3A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be...
CVE-2026-98163——In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero re...
CVE-2026-100312MEDIUM6.3A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b6...
CVE-2026-100311LOW3.5A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be...
CVE-2026-96533MEDIUM5.8The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-s...
CVE-2026-96532HIGH7.5The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling it...
CVE-2026-96531MEDIUM6.8The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before re...
CVE-2026-96526LOW2.7The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one ...
CVE-2026-96525LOW2.7The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check...
CVE-2026-96524HIGH8.8The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now