2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-41430MEDIUM6.1Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-...
CVE-2026-41319MEDIUM5.9MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in ...
CVE-2026-41318MEDIUM5.4AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-2028MEDIUM5.3The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file owne...
CVE-2026-41305MEDIUM6.1PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract ...
CVE-2026-40254MEDIUM6.1FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path...
CVE-2026-40099MEDIUM6.5Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perfor...
CVE-2026-31956MEDIUM4.3Xibo is an open source digital signage platform with a web content management system and Windows display player software...
CVE-2026-31955MEDIUM4.9Xibo is an open source digital signage platform with a web content management system and Windows display player software...
CVE-2026-31953MEDIUM5.4Xibo is an open source digital signage platform with a web content management system and Windows display player software...
CVE-2026-40431MEDIUM6.9A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all adm...
CVE-2026-29197MEDIUM4.3In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/log...
CVE-2026-29050MEDIUM6.1melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version ...
CVE-2026-25720MEDIUM5.4A vulnerability exists in SenseLive X3050’s web management interface due to improper session lifetime enforcement, allo...
CVE-2026-1789MEDIUM6.9A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive informat...
CVE-2026-41360MEDIUM6.7OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operan...
CVE-2026-41358MEDIUM5.4OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to ...
CVE-2026-41356MEDIUM5.4OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previ...
CVE-2026-41354MEDIUM5.3OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows leg...
CVE-2026-41351MEDIUM6.3OpenClaw before 2026.3.31 contains a replay detection bypass vulnerability in webhook signature handling that treats Bas...
CVE-2026-41350MEDIUM5.3OpenClaw before 2026.3.31 contains a session visibility bypass vulnerability where the session_status function fails to ...
CVE-2026-41348MEDIUM5.4OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command and autocomplete paths...
CVE-2026-41345MEDIUM6OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Aut...
CVE-2026-41343MEDIUM6.9OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers...
CVE-2026-41341MEDIUM5.4OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now