2026 CVE Vulnerabilities
51,171 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32050 | MEDIUM | 5.3 | 0.2% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling th... |
| CVE-2026-32044 | MEDIUM | 6.7 | 0.1% | Mar 21, 2026 | OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypas... |
| CVE-2026-4083 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Scoreboard for HTML5 Games Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'scoreboar... |
| CVE-2026-3577 | MEDIUM | 4.4 | 0.2% | Mar 21, 2026 | The Keep Backup Daily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the backup title alias (`val... |
| CVE-2026-3572 | MEDIUM | 6.1 | 0.3% | Mar 21, 2026 | The iTracker360 plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting ... |
| CVE-2026-3567 | MEDIUM | 5.3 | 0.2% | Mar 21, 2026 | The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up... |
| CVE-2026-3516 | MEDIUM | 6.4 | 0.3% | Mar 21, 2026 | The Contact List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_cl_map_iframe' parameter in... |
| CVE-2026-3474 | MEDIUM | 4.9 | 0.4% | Mar 21, 2026 | The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to arbitrary file read via path ... |
| CVE-2026-3350 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Image Alt Text Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all v... |
| CVE-2026-33428 | MEDIUM | 6.5 | 0.3% | Mar 21, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a non-staf... |
| CVE-2026-33425 | MEDIUM | 5.3 | 0.2% | Mar 21, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, unauthenti... |
| CVE-2026-33424 | MEDIUM | 4.3 | 0.2% | Mar 21, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an attacke... |
| CVE-2026-33238 | MEDIUM | 4.3 | 0.4% | Mar 21, 2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, the `listFiles.json.php` endpoint accepts a `path` ... |
| CVE-2026-33237 | MEDIUM | 5.5 | 0.3% | Mar 21, 2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/... |
| CVE-2026-2430 | MEDIUM | 6.4 | 0.2% | Mar 21, 2026 | The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the lazy-loading image processing ... |
| CVE-2026-2352 | MEDIUM | 6.4 | 0.3% | Mar 21, 2026 | The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ao_post_preload' meta value i... |
| CVE-2026-3864 | MEDIUM | 6.5 | 0.5% | Mar 20, 2026 | A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was... |
| CVE-2026-33423 | MEDIUM | 4.3 | 0.2% | Mar 20, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, staff can ... |
| CVE-2026-33422 | MEDIUM | 4.3 | 0.3% | Mar 20, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `ip_a... |
| CVE-2026-33411 | MEDIUM | 5.4 | 0.2% | Mar 20, 2026 | Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a pote... |
| CVE-2026-33291 | MEDIUM | 5.4 | 0.2% | Mar 20, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators... |
| CVE-2026-33251 | MEDIUM | 5.4 | 0.2% | Mar 20, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authori... |
| CVE-2026-33230 | MEDIUM | 6.1 | 0.3% | Mar 20, 2026 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a... |
| CVE-2026-33221 | MEDIUM | 5.3 | 0.2% | Mar 20, 2026 | Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.12.0, the storage service's file upload ha... |
| CVE-2026-33209 | MEDIUM | 6.1 | 0.3% | Mar 20, 2026 | Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.30.3, a reflected cross-site script... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now