2026 CVE Vulnerabilities

51,297 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-42435HIGH8.8OpenClaw versions from 2026.2.22 before 2026.4.12 contain an insufficient shell-wrapper detection vulnerability allowing...
CVE-2026-42434HIGH8.8OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override...
CVE-2026-42433HIGH7.1OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to a...
CVE-2026-6322HIGH7.5fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as ...
CVE-2026-43870HIGH7.3Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutra...
CVE-2026-3359HIGH7.5The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Inj...
CVE-2026-43869HIGH7.3Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift:...
CVE-2026-6180HIGH8.1A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under spe...
CVE-2026-5192HIGH7.5The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Trave...
CVE-2026-7812HIGH7.3A vulnerability was found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The impacted element is the...
CVE-2026-7811HIGH7.3A vulnerability has been found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The affected element i...
CVE-2026-7810HIGH7.3A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the fu...
CVE-2026-4803HIGH7.2The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter ...
CVE-2026-3456HIGH7.5The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL...
CVE-2026-35228HIGH8.7Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The ...
CVE-2026-5100HIGH7.5The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versio...
CVE-2026-44028HIGH7.5An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser ...
CVE-2026-7788HIGH7.3A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. The af...
CVE-2026-7785HIGH7.3A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f2...
CVE-2026-7784HIGH7.3A vulnerability has been found in RTGS2017 NagaAgent up to 5.1.0. This issue affects some unknown processing of the file...
CVE-2026-7791HIGH8.5Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpace...
CVE-2026-7776HIGH7.5Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition ...
CVE-2026-7768HIGH7.5@fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit ...
CVE-2026-6321HIGH7.5fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize()...
CVE-2026-41927HIGH8.3WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains a stack-based buffer overflow vulnerability in the firew...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now