2026 CVE Vulnerabilities
49,883 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41300 | MEDIUM | 6.9 | 0.3% | Apr 21, 2026 | OpenClaw before 2026.3.31 contains a trust-decline vulnerability that preserves attacker-discovered endpoints in remote ... |
| CVE-2026-41298 | MEDIUM | 5.4 | 0.2% | Apr 21, 2026 | OpenClaw before 2026.4.2 fails to enforce write scopes on the POST /sessions/:sessionKey/kill endpoint in identity-beari... |
| CVE-2026-41285 | MEDIUM | 4.3 | 0.2% | Apr 21, 2026 | In OpenBSD through 7.8, the slaacd and rad daemons have an infinite loop when they receive a crafted ICMPv6 Neighbor Dis... |
| CVE-2026-40045 | MEDIUM | 5.9 | 0.1% | Apr 21, 2026 | OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials... |
| CVE-2026-35588 | MEDIUM | 6.3 | 0.2% | Apr 21, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`g... |
| CVE-2026-34839 | MEDIUM | 6.5 | 0.4% | Apr 21, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes ... |
| CVE-2026-5721 | MEDIUM | 4.7 | 0.3% | Apr 20, 2026 | The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stor... |
| CVE-2026-34082 | MEDIUM | 4.3 | 0.2% | Apr 20, 2026 | Dify is an open-source LLM app development platform. Prior to 1.13.1, the method `DELETE /console/api/installed-apps/<ap... |
| CVE-2026-22051 | MEDIUM | 4.3 | 0.2% | Apr 20, 2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Di... |
| CVE-2026-0930 | MEDIUM | 4.3 | 0.2% | Apr 20, 2026 | Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated us... |
| CVE-2026-4852 | MEDIUM | 6.4 | 0.2% | Apr 20, 2026 | The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Site ... |
| CVE-2026-33431 | MEDIUM | 6.5 | 0.4% | Apr 20, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POS... |
| CVE-2026-29647 | MEDIUM | 6.5 | 0.2% | Apr 20, 2026 | In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state ... |
| CVE-2026-6550 | MEDIUM | 5.7 | 0.1% | Apr 20, 2026 | Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and ... |
| CVE-2026-6060 | MEDIUM | 4.5 | 0.2% | Apr 20, 2026 | A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a... |
| CVE-2026-41389 | MEDIUM | 6.3 | 0.3% | Apr 20, 2026 | OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing ... |
| CVE-2026-39112 | MEDIUM | 5.4 | 0.2% | Apr 20, 2026 | Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in ... |
| CVE-2026-26399 | MEDIUM | 5.3 | 0.2% | Apr 20, 2026 | A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function... |
| CVE-2026-23758 | MEDIUM | 5.4 | 0.2% | Apr 20, 2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows ... |
| CVE-2026-23757 | MEDIUM | 5.4 | 0.1% | Apr 20, 2026 | GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title p... |
| CVE-2026-23756 | MEDIUM | 5.4 | 0.1% | Apr 20, 2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the s... |
| CVE-2026-23753 | MEDIUM | 4.8 | 0.2% | Apr 20, 2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality... |
| CVE-2026-23752 | MEDIUM | 4.8 | 0.2% | Apr 20, 2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editi... |
| CVE-2026-40098 | MEDIUM | 5.4 | 0.2% | Apr 20, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-35154 | MEDIUM | 6.7 | 0.1% | Apr 20, 2026 | Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now