2026 CVE Vulnerabilities
50,562 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6143 | MEDIUM | 6.3 | 0.2% | Apr 13, 2026 | A security flaw has been discovered in farion1231 cc-switch up to 3.12.3. Affected by this issue is some unknown functio... |
| CVE-2026-6141 | MEDIUM | 6.3 | 1.1% | Apr 13, 2026 | A vulnerability was determined in danielmiessler Personal_AI_Infrastructure up to 2.3.0. Affected is an unknown function... |
| CVE-2026-6125 | MEDIUM | 6.3 | 0.3% | Apr 12, 2026 | A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpressio... |
| CVE-2026-6119 | MEDIUM | 6.3 | 0.3% | Apr 12, 2026 | A vulnerability was identified in AstrBotDevs AstrBot up to 4.22.1. The affected element is the function post_data.get o... |
| CVE-2026-6118 | MEDIUM | 6.3 | 2.3% | Apr 12, 2026 | A vulnerability was determined in AstrBotDevs AstrBot up to 4.22.1. Impacted is the function add_mcp_server of the file ... |
| CVE-2026-6117 | MEDIUM | 6.3 | 0.2% | Apr 12, 2026 | A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1. This issue affects the function install_plugin_upload of ... |
| CVE-2026-6111 | MEDIUM | 6.5 | 0.3% | Apr 12, 2026 | A security flaw has been discovered in FoundationAgents MetaGPT up to 0.8.1. This impacts the function decode_image of t... |
| CVE-2026-1116 | MEDIUM | 6.1 | 0.3% | Apr 12, 2026 | A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in p... |
| CVE-2026-6108 | MEDIUM | 6.3 | 1.3% | Apr 12, 2026 | A vulnerability was found in 1Panel-dev MaxKB up to 2.6.1. The affected element is the function execute of the file apps... |
| CVE-2026-6107 | MEDIUM | 5.1 | 0.2% | Apr 12, 2026 | A flaw has been found in 1Panel-dev MaxKB up to 2.6.1. This issue affects some unknown processing of the file apps/commo... |
| CVE-2026-23900 | MEDIUM | 6.5 | 0.2% | Apr 11, 2026 | Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been d... |
| CVE-2026-5226 | MEDIUM | 6.1 | 0.5% | Apr 11, 2026 | The Optimole – Optimize Images in Real Time plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL... |
| CVE-2026-5207 | MEDIUM | 6.5 | 0.4% | Apr 11, 2026 | The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and i... |
| CVE-2026-4979 | MEDIUM | 5 | 0.3% | Apr 11, 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre... |
| CVE-2026-4895 | MEDIUM | 6.4 | 0.4% | Apr 11, 2026 | The GreenShift - Animation and Page Builder Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ... |
| CVE-2026-3498 | MEDIUM | 6.4 | 0.2% | Apr 11, 2026 | The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clientId' block attribute... |
| CVE-2026-3371 | MEDIUM | 4.3 | 0.4% | Apr 11, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere... |
| CVE-2026-3358 | MEDIUM | 5.4 | 0.4% | Apr 11, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized private course e... |
| CVE-2026-40354 | MEDIUM | 6.3 | 0.1% | Apr 11, 2026 | Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host c... |
| CVE-2026-3691 | MEDIUM | 5.3 | 0.5% | Apr 11, 2026 | OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo... |
| CVE-2026-3689 | MEDIUM | 6.5 | 0.9% | Apr 11, 2026 | OpenClaw Canvas Path Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to discl... |
| CVE-2026-40199 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pa... |
| CVE-2026-33119 | MEDIUM | 5.4 | 0.3% | Apr 10, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-33118 | MEDIUM | 4.3 | 0.6% | Apr 10, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-5724 | MEDIUM | 6.3 | 0.5% | Apr 10, 2026 | The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now