2026 CVE Vulnerabilities

53,091 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-28724MEDIUM4.3Unauthorized data access due to insufficient access control validation. The following products are affected: Acronis Cyb...
CVE-2026-28723MEDIUM4.3Unauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Prot...
CVE-2026-28720MEDIUM4.3Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acr...
CVE-2026-28719MEDIUM4.3Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cy...
CVE-2026-28717MEDIUM5Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Pro...
CVE-2026-28716MEDIUM4.4Information disclosure and manipulation due to improper authorization checks. The following products are affected: Acron...
CVE-2026-28715MEDIUM6.5Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cybe...
CVE-2026-28714MEDIUM4.8Unnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect...
CVE-2026-28712MEDIUM6.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec...
CVE-2026-28711MEDIUM6.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protec...
CVE-2026-28709MEDIUM4.3Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cy...
CVE-2026-27770MEDIUM6.9Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-26124MEDIUM6.7'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
CVE-2026-26122MEDIUM6.5Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized attacker to disclose...
CVE-2026-23651MEDIUM6.7Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
CVE-2026-3606MEDIUM5.5A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segme...
CVE-2026-2593MEDIUM6.4The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2026-29606MEDIUM6.5OpenClaw versions prior to 2026.2.14 contain a webhook signature-verification bypass in the voice-call extension that al...
CVE-2026-28486MEDIUM5.5OpenClaw versions 2026.1.16-2 prior to 2026.2.14 contain a path traversal vulnerability in archive extraction during ins...
CVE-2026-28480MEDIUM6.9OpenClaw versions prior to 2026.2.14 contain an authorization bypass vulnerability where Telegram allowlist matching acc...
CVE-2026-28476MEDIUM5.8OpenClaw versions prior to 2026.2.14 contain a server-side request forgery vulnerability in the optional Tlon Urbit exte...
CVE-2026-28471MEDIUM6.3OpenClaw version 2026.1.14-1 prior to 2026.2.2, with the Matrix plugin installed and enabled, contain a vulnerability in...
CVE-2026-28463MEDIUM5.5OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist valida...
CVE-2026-28458MEDIUM5.4OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed ...
CVE-2026-28452MEDIUM6.5OpenClaw versions prior to 2026.2.14 contain a denial of service vulnerability in the extractArchive function within src...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now