2026 CVE Vulnerabilities

49,221 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-5306MEDIUM5.4The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unau...
CVE-2026-6809MEDIUM6.4The Social Post Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Threads embed handler in...
CVE-2026-6725MEDIUM6.4The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' ...
CVE-2026-6551MEDIUM6.4The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' a...
CVE-2026-7217MEDIUM5.5A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read...
CVE-2026-0711MEDIUM6.8A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions ...
CVE-2026-7200MEDIUM4.3A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is some unknown ...
CVE-2026-7196MEDIUM6.3A security vulnerability has been detected in CodeAstro Online Classroom 1.0. Affected is an unknown function of the fil...
CVE-2026-41372MEDIUM6.9OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing byp...
CVE-2026-41367MEDIUM5.3OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord butto...
CVE-2026-41366MEDIUM6OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that all...
CVE-2026-41365MEDIUM5.4OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph ...
CVE-2026-41363MEDIUM6.5OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploa...
CVE-2026-41362MEDIUM4.3OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation vulnerability in the Zalo webhook repla...
CVE-2026-40977MEDIUM6.7When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file'...
CVE-2026-7183MEDIUM5.5A vulnerability has been found in aligungr UERANSIM up to 3.2.7. The affected element is the function rls::DecodeRlsMess...
CVE-2026-7179MEDIUM5.3A security vulnerability has been detected in OSPG binwalk up to 2.4.3. This vulnerability affects the function read_nul...
CVE-2026-5362MEDIUM5.4An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed...
CVE-2026-29971MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in WebFileSys version before 2.32.0 and fixed in v.2.32.0. U...
CVE-2026-7150MEDIUM6.3A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the ...
CVE-2026-7148MEDIUM6.3A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Execut...
CVE-2026-40970MEDIUM6.8When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verificat...
CVE-2026-35902MEDIUM6.2The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication att...
CVE-2026-35901MEDIUM4.4A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attac...
CVE-2026-7145MEDIUM5.4A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/C...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now