2026 CVE Vulnerabilities

53,345 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-32978HIGH7.5OpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable f...
CVE-2026-32972HIGH7.1OpenClaw before 2026.3.11 contains an authorization bypass vulnerability allowing authenticated operators with only oper...
CVE-2026-32914HIGH8.8OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config and /debug command handle...
CVE-2026-5043HIGH8.8A weakness has been identified in Belkin F9K1122 1.00.33. The impacted element is the function formSetPassword of the fi...
CVE-2026-5042HIGH8.8A security flaw has been discovered in Belkin F9K1122 1.00.33. The affected element is the function formCrossBandSwitch ...
CVE-2026-5036HIGH8.8A vulnerability was found in Tenda 4G06 04.06.01.29. This vulnerability affects the function fromDhcpListClient of the f...
CVE-2026-5024HIGH8.8A vulnerability was found in D-Link DIR-513 1.10. This issue affects the function formSetEmail of the file /goform/formS...
CVE-2026-5021HIGH8.8A flaw has been found in Tenda F453 1.0.0.3. This affects the function fromPPTPUserSetting of the file /goform/PPTPUserS...
CVE-2026-5016HIGH7.3A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the ...
CVE-2026-5012HIGH7.3A flaw has been found in elecV2 elecV2P up to 3.8.3. This issue affects the function pm2run of the file /rpc. Executing ...
CVE-2026-5004HIGH8.8A vulnerability was determined in Wavlink WL-WN579X3-C 231124. This impacts the function sub_4019FC of the file /cgi-bin...
CVE-2026-5002HIGH7.3A vulnerability has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The impacted el...
CVE-2026-5001HIGH7.3A flaw has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The affected element is ...
CVE-2026-5000HIGH7.3A vulnerability was detected in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. Impacted is the f...
CVE-2026-4998HIGH7.3A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor...
CVE-2026-4996HIGH7.3A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_questi...
CVE-2026-4987HIGH7.5The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amo...
CVE-2026-1679HIGH7.8The eswifi socket offload driver copies user-provided payloads into a fixed buffer without checking available space; ove...
CVE-2026-4248HIGH8The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl...
CVE-2026-33991HIGH8.8WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php...
CVE-2026-4990HIGH7.3A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the ...
CVE-2026-34226HIGH7.5Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Versions prior to 20.8.9...
CVE-2026-33980HIGH8.1Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL querie...
CVE-2026-33979HIGH8.2Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.hea...
CVE-2026-33955HIGH8.6Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now