2026 CVE Vulnerabilities

53,405 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-1313HIGH8.3The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in...
CVE-2026-4302HIGH7.2The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up ...
CVE-2026-32067HIGH8.1OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability in the pairing-store access control f...
CVE-2026-32057HIGH7.1OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pair...
CVE-2026-32055HIGH8.2OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows...
CVE-2026-32054HIGH7.8OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path...
CVE-2026-32051HIGH8.8OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers wi...
CVE-2026-32049HIGH8.7OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering ...
CVE-2026-32043HIGH7OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.run exec...
CVE-2026-32042HIGH8.8OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device ide...
CVE-2026-3368HIGH7.2The Injection Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious query parameter name...
CVE-2026-33427HIGH7.5Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an unauthe...
CVE-2026-32666HIGH7.5WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does ...
CVE-2026-25086HIGH7.7Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to cra...
CVE-2026-4508HIGH7.3A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file ...
CVE-2026-33476HIGH7.5SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated f...
CVE-2026-33243HIGH8.2barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport t...
CVE-2026-33236HIGH8.1NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a...
CVE-2026-33231HIGH7.5NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a...
CVE-2026-33226HIGH8.7Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and pr...
CVE-2026-33204HIGH7.5SimpleJWT is a simple JSON web token library written in PHP. Prior to version 1.1.1, an unauthenticated attacker can per...
CVE-2026-33203HIGH7.5SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts una...
CVE-2026-33180HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio...
CVE-2026-31904HIGH8.7The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc...
CVE-2026-31903HIGH8.7The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now