2026 CVE Vulnerabilities

50,996 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-5106MEDIUM4.8A flaw has been found in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file...
CVE-2026-33574MEDIUM4.7OpenClaw before 2026.3.8 contains a path traversal vulnerability in the skills download installer that validates the too...
CVE-2026-33572MEDIUM5.5OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local u...
CVE-2026-32979MEDIUM6.7OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local cod...
CVE-2026-32923MEDIUM5.4OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild reaction ingestion that fails ...
CVE-2026-32919MEDIUM6.9OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-on...
CVE-2026-23400MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: rust_binder: call set_notification_done() without p...
CVE-2026-5041MEDIUM4.7A vulnerability was identified in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is the fu...
CVE-2026-5031MEDIUM4.3A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_...
CVE-2026-5023MEDIUM5.3A vulnerability has been found in DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6. This vulner...
CVE-2026-2602MEDIUM6.4The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter...
CVE-2026-5015MEDIUM4.3A vulnerability was determined in elecV2 elecV2P up to 3.8.3. The impacted element is an unknown function of the file /l...
CVE-2026-5014MEDIUM5.5A vulnerability was found in elecV2 elecV2P up to 3.8.3. The affected element is the function path.join of the file /log...
CVE-2026-5013MEDIUM5.5A vulnerability has been found in elecV2 elecV2P up to 3.8.3. Impacted is the function path.join of the file /store/:key...
CVE-2026-5011MEDIUM6.3A vulnerability was detected in elecV2 elecV2P up to 3.8.3. This vulnerability affects the function runJSFile of the fil...
CVE-2026-5007MEDIUM5.3A vulnerability was identified in kazuph mcp-docs-rag up to 0.5.0. Affected is the function cloneRepository of the file ...
CVE-2026-5003MEDIUM5.5A vulnerability was found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. This affects the fun...
CVE-2026-4999MEDIUM6.3A security vulnerability has been detected in z-9527 admin up to 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2. This issue af...
CVE-2026-4997MEDIUM5.5A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of ...
CVE-2026-2595MEDIUM5.4The Quads Ads Manager for Google AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u...
CVE-2026-2442MEDIUM5.3The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralizatio...
CVE-2026-23399MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nf_tables: nft_dynset: fix possible stateful expres...
CVE-2026-1307MEDIUM6.5The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Informati...
CVE-2026-4992MEDIUM4.3A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/op...
CVE-2026-4991MEDIUM5.1A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown funct...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now