2026 CVE Vulnerabilities

50,562 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6143MEDIUM6.3A security flaw has been discovered in farion1231 cc-switch up to 3.12.3. Affected by this issue is some unknown functio...
CVE-2026-6141MEDIUM6.3A vulnerability was determined in danielmiessler Personal_AI_Infrastructure up to 2.3.0. Affected is an unknown function...
CVE-2026-6125MEDIUM6.3A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpressio...
CVE-2026-6119MEDIUM6.3A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the function post_data.get o...
CVE-2026-6118MEDIUM6.3A vulnerability was determined in AstrBotDevs AstrBot up to 4.22.1. Impacted is the function add_mcp_server of the file ...
CVE-2026-6117MEDIUM6.3A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1. This issue affects the function install_plugin_upload of ...
CVE-2026-6111MEDIUM6.5A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.1. This impacts the function decode_image of t...
CVE-2026-1116MEDIUM6.1A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in p...
CVE-2026-6108MEDIUM6.3A vulnerability was found in 1Panel-dev MaxKB up to 2.6.1. The affected element is the function execute of the file apps...
CVE-2026-6107MEDIUM5.1A flaw has been found in 1Panel-dev MaxKB up to 2.6.1. This issue affects some unknown processing of the file apps/commo...
CVE-2026-23900MEDIUM6.5Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been d...
CVE-2026-5226MEDIUM6.1The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL...
CVE-2026-5207MEDIUM6.5The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and i...
CVE-2026-4979MEDIUM5The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre...
CVE-2026-4895MEDIUM6.4The GreenShift - Animation and Page Builder Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ...
CVE-2026-3498MEDIUM6.4The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clientId' block attribute...
CVE-2026-3371MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere...
CVE-2026-3358MEDIUM5.4The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized private course e...
CVE-2026-40354MEDIUM6.3Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host c...
CVE-2026-3691MEDIUM5.3OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo...
CVE-2026-3689MEDIUM6.5OpenClaw Canvas Path Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to discl...
CVE-2026-40199MEDIUM6.5Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pa...
CVE-2026-33119MEDIUM5.4User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-33118MEDIUM4.3User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-5724MEDIUM6.3The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now