2026 CVE Vulnerabilities

51,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-32843MEDIUM5.1Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting...
CVE-2026-21788MEDIUM5.4HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbi...
CVE-2026-3475MEDIUM5.3The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all ver...
CVE-2026-4120MEDIUM6.4The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2026-4068MEDIUM4.3The Add Custom Fields to Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2026-4006MEDIUM6.4The Simple Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' post meta...
CVE-2026-2571MEDIUM4.3The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2026-27091MEDIUM6.3Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured Access...
CVE-2026-28070MEDIUM5.3Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting Incorrectly Configured Access Con...
CVE-2026-28044MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket...
CVE-2026-27397MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro ...
CVE-2026-1276MEDIUM5.4IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows a...
CVE-2026-31997MEDIUM6.7OpenClaw versions prior to 2026.3.1 fail to pin executable identity for non-path-like argv[0] tokens in system.run appro...
CVE-2026-31996MEDIUM4.4OpenClaw versions prior to 2026.2.19 tools.exec.safeBins contains an input validation bypass vulnerability that allows a...
CVE-2026-31993MEDIUM6.4OpenClaw versions prior to 2026.2.22 contain an allowlist parsing mismatch vulnerability in the macOS companion app that...
CVE-2026-31991MEDIUM4.6OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where Signal group allowlist policy i...
CVE-2026-31989MEDIUM6.3OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation redirect ...
CVE-2026-29608MEDIUM6.7OpenClaw 2026.3.1 contains an approval integrity vulnerability in system.run node-host execution where argv rewriting ch...
CVE-2026-28449MEDIUM6.5OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed ...
CVE-2026-27670MEDIUM5.8OpenClaw versions prior to 2026.3.2 contain a race condition vulnerability in ZIP extraction that allows local attackers...
CVE-2026-32743MEDIUM6.5PX4 is an open-source autopilot stack for drones and unmanned vehicles. Versions 1.17.0-rc2 and below are vulnerable to ...
CVE-2026-32736MEDIUM4.3The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. An Insecure Direct Object...
CVE-2026-33163MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-33042MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32742MEDIUM4.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now