2026 CVE Vulnerabilities

53,618 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-32063HIGH7.8OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generati...
CVE-2026-32062HIGH8.7OpenClaw versions 2026.2.21-2 up to, but not including, 2026.2.22, and @openclaw/voice-call versions 2026.2.21 up to, bu...
CVE-2026-32060HIGH8.8OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to writ...
CVE-2026-32059HIGH8.8OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly valida...
CVE-2026-3943HIGH7.3A vulnerability was found in H3C ACG1000-AK230 up to 20260227. This affects an unknown part of the file /webui/?aaa_port...
CVE-2026-3178HIGH7.2The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' param...
CVE-2026-3805HIGH7.5When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already free...
CVE-2026-3231HIGH7.2The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2026-1993HIGH8.8The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in ver...
CVE-2026-1992HIGH8.8The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in ...
CVE-2026-1454HIGH7.2The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2026-1708HIGH7.5The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to bli...
CVE-2026-31844HIGH8.8An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion...
CVE-2026-3222HIGH7.5The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all ...
CVE-2026-2626HIGH8.1The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function...
CVE-2026-2466HIGH7.1The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2026-20892HIGH8.6Code injection vulnerability exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker with administrative privil...
CVE-2026-2413HIGH7.5The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all ver...
CVE-2026-23816HIGH7.2A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute...
CVE-2026-23815HIGH7.2A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high p...
CVE-2026-23814HIGH8.8A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remo...
CVE-2026-3453HIGH8.1The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu...
CVE-2026-21361HIGH8.1Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a ...
CVE-2026-21311HIGH8Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a ...
CVE-2026-21309HIGH7.5Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now