2026 CVE Vulnerabilities

51,171 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-32050MEDIUM5.3OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling th...
CVE-2026-32044MEDIUM6.7OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypas...
CVE-2026-4083MEDIUM6.4The Scoreboard for HTML5 Games Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'scoreboar...
CVE-2026-3577MEDIUM4.4The Keep Backup Daily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the backup title alias (`val...
CVE-2026-3572MEDIUM6.1The iTracker360 plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting ...
CVE-2026-3567MEDIUM5.3The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up...
CVE-2026-3516MEDIUM6.4The Contact List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_cl_map_iframe' parameter in...
CVE-2026-3474MEDIUM4.9The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to arbitrary file read via path ...
CVE-2026-3350MEDIUM6.4The Image Alt Text Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all v...
CVE-2026-33428MEDIUM6.5Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a non-staf...
CVE-2026-33425MEDIUM5.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, unauthenti...
CVE-2026-33424MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an attacke...
CVE-2026-33238MEDIUM4.3WWBN AVideo is an open source video platform. Prior to version 26.0, the `listFiles.json.php` endpoint accepts a `path` ...
CVE-2026-33237MEDIUM5.5WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/...
CVE-2026-2430MEDIUM6.4The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the lazy-loading image processing ...
CVE-2026-2352MEDIUM6.4The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ao_post_preload' meta value i...
CVE-2026-3864MEDIUM6.5A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was...
CVE-2026-33423MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, staff can ...
CVE-2026-33422MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `ip_a...
CVE-2026-33411MEDIUM5.4Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a pote...
CVE-2026-33291MEDIUM5.4Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators...
CVE-2026-33251MEDIUM5.4Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authori...
CVE-2026-33230MEDIUM6.1NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a...
CVE-2026-33221MEDIUM5.3Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.12.0, the storage service's file upload ha...
CVE-2026-33209MEDIUM6.1Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.30.3, a reflected cross-site script...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now