2026 CVE Vulnerabilities

49,873 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6765MEDIUM5.3Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, ...
CVE-2026-6764MEDIUM6.5Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Fire...
CVE-2026-6763MEDIUM6.5Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thund...
CVE-2026-6762MEDIUM6.3Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firef...
CVE-2026-6757MEDIUM6.3Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.1...
CVE-2026-6755MEDIUM6.5Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-32147MEDIUM4.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP ssh (ssh_sftp...
CVE-2026-3317MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present i...
CVE-2026-6712MEDIUM4.4The Website LLMs.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version...
CVE-2026-6711MEDIUM6.1The Website LLMs.txt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all...
CVE-2026-6703MEDIUM4.3The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access in ...
CVE-2026-31370MEDIUM6.3Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect serv...
CVE-2026-6675MEDIUM5.3The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Em...
CVE-2026-6674MEDIUM6.5The Plugin: CMS für Motorrad Werkstätten plugin for WordPress is vulnerable to SQL Injection via the 'arttype' parameter...
CVE-2026-6058MEDIUM5.7** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 fi...
CVE-2026-39886MEDIUM5.3OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-39946MEDIUM4.9OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privile...
CVE-2026-39396MEDIUM6.5OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` i...
CVE-2026-39378MEDIUM6.5The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versi...
CVE-2026-39377MEDIUM6.5The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions...
CVE-2026-41331MEDIUM6.9OpenClaw before 2026.3.31 contains a resource consumption vulnerability in Telegram audio preflight transcription that a...
CVE-2026-41330MEDIUM4.4OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to prop...
CVE-2026-41302MEDIUM6.3OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functi...
CVE-2026-41301MEDIUM6.9OpenClaw versions 2026.3.22 before 2026.3.31 contain a signature verification bypass vulnerability in the Nostr DM ingre...
CVE-2026-41300MEDIUM6.9OpenClaw before 2026.3.31 contains a trust-decline vulnerability that preserves attacker-discovered endpoints in remote ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now