2026 CVE Vulnerabilities
64,705 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100605 | HIGH | 7.1 | — | Sep 26, 2026 | Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API k... |
| CVE-2026-100315 | HIGH | 7.3 | — | Sep 26, 2026 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. ... |
| CVE-2026-100314 | HIGH | 7.3 | — | Sep 26, 2026 | A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db... |
| CVE-2026-96532 | HIGH | 7.5 | 0.1% | Sep 26, 2026 | The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling it... |
| CVE-2026-96524 | HIGH | 8.8 | 0.1% | Sep 26, 2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for c... |
| CVE-2026-85081 | HIGH | 7.5 | 0.2% | Sep 26, 2026 | The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPres... |
| CVE-2026-84096 | HIGH | 8 | 0.2% | Sep 26, 2026 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on the AJAX handler that sa... |
| CVE-2026-84095 | HIGH | 8 | 0.2% | Sep 26, 2026 | The wp-review-slider-pro WordPress plugin before 12.7.12 does not perform a capability check on one of its AJAX handlers... |
| CVE-2026-16591 | HIGH | 7.2 | 0.2% | Sep 26, 2026 | The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields... |
| CVE-2026-100599 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands... |
| CVE-2026-100598 | HIGH | 7.1 | — | Sep 26, 2026 | OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a rea... |
| CVE-2026-100597 | HIGH | 7.8 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShe... |
| CVE-2026-100596 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through... |
| CVE-2026-100589 | HIGH | 8.3 | — | Sep 26, 2026 | OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessi... |
| CVE-2026-100588 | HIGH | 8.3 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser contro... |
| CVE-2026-100587 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation c... |
| CVE-2026-100586 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings.... |
| CVE-2026-100585 | HIGH | 8 | — | Sep 26, 2026 | OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude C... |
| CVE-2026-100580 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a m... |
| CVE-2026-100579 | HIGH | 7.6 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity... |
| CVE-2026-100578 | HIGH | 7.6 | — | Sep 26, 2026 | OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the ... |
| CVE-2026-100575 | HIGH | 8.8 | — | Sep 26, 2026 | OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disa... |
| CVE-2026-100570 | HIGH | 7.8 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the... |
| CVE-2026-100568 | HIGH | 8.3 | — | Sep 26, 2026 | OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible... |
| CVE-2026-100567 | HIGH | 8.2 | — | Sep 26, 2026 | OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gate... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now