2026 CVE Vulnerabilities

51,340 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-22320MEDIUM6.5A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Tel...
CVE-2026-22319MEDIUM4.9A stack-based buffer overflow in the device's file installation workflow allows a high-privileged attacker to send overs...
CVE-2026-22318MEDIUM4.9A stack-based buffer overflow vulnerability in the device's file transfer parameter workflow allows a high-privileged at...
CVE-2026-22316MEDIUM6.5A remote attacker with user privileges for the webUI can use the setting of the TFTP Filename with a POST Request to tri...
CVE-2026-3512MEDIUM6.1The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter...
CVE-2026-4366MEDIUM5.8A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirect...
CVE-2026-33058MEDIUM6.5Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQ...
CVE-2026-32265MEDIUM6.9The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, una...
CVE-2026-31938MEDIUM6.1jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the...
CVE-2026-31898MEDIUM6.5jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnot...
CVE-2026-31891MEDIUM6.5Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API acc...
CVE-2026-31865MEDIUM5.3Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun...
CVE-2026-2575MEDIUM5.3A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS...
CVE-2026-1926MEDIUM5.3The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2026-1780MEDIUM6.1The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all v...
CVE-2026-4268MEDIUM6.4The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgm...
CVE-2026-28499MEDIUM6.1LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correct...
CVE-2026-27545MEDIUM4.7OpenClaw versions prior to 2026.2.26 contain an approval bypass vulnerability in system.run execution that allows attack...
CVE-2026-27524MEDIUM4.3OpenClaw versions prior to 2026.2.21 accept prototype-reserved keys in runtime /debug set override object values, allowi...
CVE-2026-27522MEDIUM5.5OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon ...
CVE-2026-22217MEDIUM6.1OpenClaw version 2026.2.22 prior to 2026.2.23 contains an arbitrary code execution vulnerability in shell-env that allow...
CVE-2026-22180MEDIUM5.3OpenClaw versions prior to 2026.3.2 contain a path-confinement bypass vulnerability in browser output handling that allo...
CVE-2026-22174MEDIUM6.8OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback ...
CVE-2026-22170MEDIUM6.5OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability...
CVE-2026-29057MEDIUM6.5Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now