2026 CVE Vulnerabilities
53,405 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1313 | HIGH | 8.3 | 0.3% | Mar 21, 2026 | The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in... |
| CVE-2026-4302 | HIGH | 7.2 | 0.3% | Mar 21, 2026 | The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up ... |
| CVE-2026-32067 | HIGH | 8.1 | 0.2% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control f... |
| CVE-2026-32057 | HIGH | 7.1 | 0.3% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pair... |
| CVE-2026-32055 | HIGH | 8.2 | 0.3% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows... |
| CVE-2026-32054 | HIGH | 7.8 | 0.1% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path... |
| CVE-2026-32051 | HIGH | 8.8 | 0.4% | Mar 21, 2026 | OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers wi... |
| CVE-2026-32049 | HIGH | 8.7 | 0.5% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering ... |
| CVE-2026-32043 | HIGH | 7 | 0.1% | Mar 21, 2026 | OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.run exec... |
| CVE-2026-32042 | HIGH | 8.8 | 0.4% | Mar 21, 2026 | OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device ide... |
| CVE-2026-3368 | HIGH | 7.2 | 0.3% | Mar 21, 2026 | The Injection Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious query parameter name... |
| CVE-2026-33427 | HIGH | 7.5 | 0.2% | Mar 21, 2026 | Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an unauthe... |
| CVE-2026-32666 | HIGH | 7.5 | 0.3% | Mar 21, 2026 | WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does ... |
| CVE-2026-25086 | HIGH | 7.7 | 0.2% | Mar 21, 2026 | Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to cra... |
| CVE-2026-4508 | HIGH | 7.3 | 0.3% | Mar 20, 2026 | A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file ... |
| CVE-2026-33476 | HIGH | 7.5 | 3.3% | Mar 20, 2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated f... |
| CVE-2026-33243 | HIGH | 8.2 | 0.1% | Mar 20, 2026 | barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport t... |
| CVE-2026-33236 | HIGH | 8.1 | 0.5% | Mar 20, 2026 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a... |
| CVE-2026-33231 | HIGH | 7.5 | 0.9% | Mar 20, 2026 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a... |
| CVE-2026-33226 | HIGH | 8.7 | 0.4% | Mar 20, 2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and pr... |
| CVE-2026-33204 | HIGH | 7.5 | 0.5% | Mar 20, 2026 | SimpleJWT is a simple JSON web token library written in PHP. Prior to version 1.1.1, an unauthenticated attacker can per... |
| CVE-2026-33203 | HIGH | 7.5 | 0.5% | Mar 20, 2026 | SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts una... |
| CVE-2026-33180 | HIGH | 7.5 | 0.3% | Mar 20, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio... |
| CVE-2026-31904 | HIGH | 8.7 | 0.4% | Mar 20, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc... |
| CVE-2026-31903 | HIGH | 8.7 | 0.4% | Mar 20, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now