2026 CVE Vulnerabilities

49,883 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-41300MEDIUM6.9OpenClaw before 2026.3.31 contains a trust-decline vulnerability that preserves attacker-discovered endpoints in remote ...
CVE-2026-41298MEDIUM5.4OpenClaw before 2026.4.2 fails to enforce write scopes on the POST /sessions/:sessionKey/kill endpoint in identity-beari...
CVE-2026-41285MEDIUM4.3In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Dis...
CVE-2026-40045MEDIUM5.9OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials...
CVE-2026-35588MEDIUM6.3Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`g...
CVE-2026-34839MEDIUM6.5Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes ...
CVE-2026-5721MEDIUM4.7The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stor...
CVE-2026-34082MEDIUM4.3Dify is an open-source LLM app development platform. Prior to 1.13.1, the method `DELETE /console/api/installed-apps/<ap...
CVE-2026-22051MEDIUM4.3StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Di...
CVE-2026-0930MEDIUM4.3Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated us...
CVE-2026-4852MEDIUM6.4The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Site ...
CVE-2026-33431MEDIUM6.5Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POS...
CVE-2026-29647MEDIUM6.5In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state ...
CVE-2026-6550MEDIUM5.7Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and ...
CVE-2026-6060MEDIUM4.5A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a...
CVE-2026-41389MEDIUM6.3OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing ...
CVE-2026-39112MEDIUM5.4Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in ...
CVE-2026-26399MEDIUM5.3A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function...
CVE-2026-23758MEDIUM5.4GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows ...
CVE-2026-23757MEDIUM5.4GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title p...
CVE-2026-23756MEDIUM5.4GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the s...
CVE-2026-23753MEDIUM4.8GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality...
CVE-2026-23752MEDIUM4.8GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editi...
CVE-2026-40098MEDIUM5.4Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-35154MEDIUM6.7Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now