2026 CVE Vulnerabilities
50,996 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5106 | MEDIUM | 4.8 | 0.2% | Mar 30, 2026 | A flaw has been found in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file... |
| CVE-2026-33574 | MEDIUM | 4.7 | 0.1% | Mar 29, 2026 | OpenClaw before 2026.3.8 contains a path traversal vulnerability in the skills download installer that validates the too... |
| CVE-2026-33572 | MEDIUM | 5.5 | 0.1% | Mar 29, 2026 | OpenClaw before 2026.2.17 creates session transcript JSONL files with overly broad default permissions, allowing local u... |
| CVE-2026-32979 | MEDIUM | 6.7 | 0.1% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an approval integrity vulnerability allowing attackers to execute rewritten local cod... |
| CVE-2026-32923 | MEDIUM | 5.4 | 0.2% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an authorization bypass vulnerability in Discord guild reaction ingestion that fails ... |
| CVE-2026-32919 | MEDIUM | 6.9 | 0.1% | Mar 29, 2026 | OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing write-scoped callers to reach admin-on... |
| CVE-2026-23400 | MEDIUM | 5.5 | 0.1% | Mar 29, 2026 | In the Linux kernel, the following vulnerability has been resolved: rust_binder: call set_notification_done() without p... |
| CVE-2026-5041 | MEDIUM | 4.7 | 1.9% | Mar 29, 2026 | A vulnerability was identified in code-projects Chamber of Commerce Membership Management System 1.0. Impacted is the fu... |
| CVE-2026-5031 | MEDIUM | 4.3 | 0.2% | Mar 29, 2026 | A vulnerability was found in BichitroGan ISP Billing Software 2025.3.20. Impacted is an unknown function of the file /?_... |
| CVE-2026-5023 | MEDIUM | 5.3 | 0.6% | Mar 29, 2026 | A vulnerability has been found in DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6. This vulner... |
| CVE-2026-2602 | MEDIUM | 6.4 | 0.2% | Mar 29, 2026 | The Twentig plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'featuredImageSizeWidth' parameter... |
| CVE-2026-5015 | MEDIUM | 4.3 | 0.3% | Mar 28, 2026 | A vulnerability was determined in elecV2 elecV2P up to 3.8.3. The impacted element is an unknown function of the file /l... |
| CVE-2026-5014 | MEDIUM | 5.5 | 0.4% | Mar 28, 2026 | A vulnerability was found in elecV2 elecV2P up to 3.8.3. The affected element is the function path.join of the file /log... |
| CVE-2026-5013 | MEDIUM | 5.5 | 0.6% | Mar 28, 2026 | A vulnerability has been found in elecV2 elecV2P up to 3.8.3. Impacted is the function path.join of the file /store/:key... |
| CVE-2026-5011 | MEDIUM | 6.3 | 0.2% | Mar 28, 2026 | A vulnerability was detected in elecV2 elecV2P up to 3.8.3. This vulnerability affects the function runJSFile of the fil... |
| CVE-2026-5007 | MEDIUM | 5.3 | 0.6% | Mar 28, 2026 | A vulnerability was identified in kazuph mcp-docs-rag up to 0.5.0. Affected is the function cloneRepository of the file ... |
| CVE-2026-5003 | MEDIUM | 5.5 | 0.3% | Mar 28, 2026 | A vulnerability was found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. This affects the fun... |
| CVE-2026-4999 | MEDIUM | 6.3 | 0.3% | Mar 28, 2026 | A security vulnerability has been detected in z-9527 admin up to 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2. This issue af... |
| CVE-2026-4997 | MEDIUM | 5.5 | 0.5% | Mar 28, 2026 | A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of ... |
| CVE-2026-2595 | MEDIUM | 5.4 | 0.1% | Mar 28, 2026 | The Quads Ads Manager for Google AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u... |
| CVE-2026-2442 | MEDIUM | 5.3 | 0.3% | Mar 28, 2026 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralizatio... |
| CVE-2026-23399 | MEDIUM | 5.5 | 0.1% | Mar 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: nf_tables: nft_dynset: fix possible stateful expres... |
| CVE-2026-1307 | MEDIUM | 6.5 | 0.2% | Mar 28, 2026 | The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Informati... |
| CVE-2026-4992 | MEDIUM | 4.3 | 0.3% | Mar 27, 2026 | A flaw has been found in wandb OpenUI up to 1.0. This affects the function create_share/get_share of the file backend/op... |
| CVE-2026-4991 | MEDIUM | 5.1 | 0.2% | Mar 27, 2026 | A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown funct... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now