2026 CVE Vulnerabilities

64,705 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-100605HIGH7.1Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API k...
CVE-2026-100315HIGH7.3A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. ...
CVE-2026-100314HIGH7.3A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db...
CVE-2026-96532HIGH7.5The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling it...
CVE-2026-96524HIGH8.8The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for c...
CVE-2026-85081HIGH7.5The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPres...
CVE-2026-84096HIGH8The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that sa...
CVE-2026-84095HIGH8The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers...
CVE-2026-16591HIGH7.2The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields...
CVE-2026-100599HIGH8.8OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands...
CVE-2026-100598HIGH7.1OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a rea...
CVE-2026-100597HIGH7.8OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShe...
CVE-2026-100596HIGH8.8OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through...
CVE-2026-100589HIGH8.3OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessi...
CVE-2026-100588HIGH8.3OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser contro...
CVE-2026-100587HIGH8.8OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation c...
CVE-2026-100586HIGH8.8OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings....
CVE-2026-100585HIGH8OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude C...
CVE-2026-100580HIGH8.8OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a m...
CVE-2026-100579HIGH7.6OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity...
CVE-2026-100578HIGH7.6OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the ...
CVE-2026-100575HIGH8.8OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disa...
CVE-2026-100570HIGH7.8OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the...
CVE-2026-100568HIGH8.3OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible...
CVE-2026-100567HIGH8.2OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gate...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now