2026 CVE Vulnerabilities
49,873 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6765 | MEDIUM | 5.3 | 0.2% | Apr 21, 2026 | Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, ... |
| CVE-2026-6764 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Fire... |
| CVE-2026-6763 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thund... |
| CVE-2026-6762 | MEDIUM | 6.3 | 0.2% | Apr 21, 2026 | Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firef... |
| CVE-2026-6757 | MEDIUM | 6.3 | 0.3% | Apr 21, 2026 | Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.1... |
| CVE-2026-6755 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
| CVE-2026-32147 | MEDIUM | 4.3 | 0.4% | Apr 21, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP ssh (ssh_sftp... |
| CVE-2026-3317 | MEDIUM | 5.1 | 0.3% | Apr 21, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present i... |
| CVE-2026-6712 | MEDIUM | 4.4 | 0.2% | Apr 21, 2026 | The Website LLMs.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version... |
| CVE-2026-6711 | MEDIUM | 6.1 | 0.2% | Apr 21, 2026 | The Website LLMs.txt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all... |
| CVE-2026-6703 | MEDIUM | 4.3 | 0.2% | Apr 21, 2026 | The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access in ... |
| CVE-2026-31370 | MEDIUM | 6.3 | 0.2% | Apr 21, 2026 | Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect serv... |
| CVE-2026-6675 | MEDIUM | 5.3 | 0.3% | Apr 21, 2026 | The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Em... |
| CVE-2026-6674 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | The Plugin: CMS für Motorrad Werkstätten plugin for WordPress is vulnerable to SQL Injection via the 'arttype' parameter... |
| CVE-2026-6058 | MEDIUM | 5.7 | 0.2% | Apr 21, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 fi... |
| CVE-2026-39886 | MEDIUM | 5.3 | 0.3% | Apr 21, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-39946 | MEDIUM | 4.9 | 0.2% | Apr 21, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privile... |
| CVE-2026-39396 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` i... |
| CVE-2026-39378 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versi... |
| CVE-2026-39377 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions... |
| CVE-2026-41331 | MEDIUM | 6.9 | 0.3% | Apr 21, 2026 | OpenClaw before 2026.3.31 contains a resource consumption vulnerability in Telegram audio preflight transcription that a... |
| CVE-2026-41330 | MEDIUM | 4.4 | 0.1% | Apr 21, 2026 | OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to prop... |
| CVE-2026-41302 | MEDIUM | 6.3 | 0.2% | Apr 21, 2026 | OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functi... |
| CVE-2026-41301 | MEDIUM | 6.9 | 0.3% | Apr 21, 2026 | OpenClaw versions 2026.3.22 before 2026.3.31 contain a signature verification bypass vulnerability in the Nostr DM ingre... |
| CVE-2026-41300 | MEDIUM | 6.9 | 0.3% | Apr 21, 2026 | OpenClaw before 2026.3.31 contains a trust-decline vulnerability that preserves attacker-discovered endpoints in remote ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now