2026 CVE Vulnerabilities

55,393 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-1069HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an...
CVE-2026-3013HIGH8.7Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attac...
CVE-2026-30902HIGH7.8Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user to conduct an escalati...
CVE-2026-30901HIGH7.8Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduc...
CVE-2026-30900HIGH7.8Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated...
CVE-2026-3496HIGH7.5The JetBooking plugin for WordPress is vulnerable to SQL Injection via the 'check_in_date' parameter in all versions up ...
CVE-2026-32063HIGH7.8OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injection vulnerability in systemd unit file generati...
CVE-2026-32062HIGH8.7OpenClaw versions 2026.2.21-2 up to, but not including, 2026.2.22, and @openclaw/voice-call versions 2026.2.21 up to, bu...
CVE-2026-32060HIGH8.8OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to writ...
CVE-2026-32059HIGH8.8OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly valida...
CVE-2026-3943HIGH7.3A vulnerability was found in H3C ACG1000-AK230 up to 20260227. This affects an unknown part of the file /webui/?aaa_port...
CVE-2026-3178HIGH7.2The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' param...
CVE-2026-3805HIGH7.5When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already free...
CVE-2026-3231HIGH7.2The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2026-1993HIGH8.8The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in ver...
CVE-2026-1992HIGH8.8The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in ...
CVE-2026-1454HIGH7.2The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2026-1708HIGH7.5The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to bli...
CVE-2026-31844HIGH8.8An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion...
CVE-2026-3222HIGH7.5The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all ...
CVE-2026-2626HIGH8.1The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function...
CVE-2026-2466HIGH7.1The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2026-20892HIGH8.6Code injection vulnerability exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker with administrative privil...
CVE-2026-2413HIGH7.5The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all ver...
CVE-2026-23816HIGH7.2A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now