2026 CVE Vulnerabilities

44,067 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-48836CRITICAL10Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.
CVE-2026-45439CRITICAL9.3Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.
CVE-2026-42665CRITICAL9.3Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.
CVE-2026-42639CRITICAL9.3Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.
CVE-2026-42386CRITICAL9.3Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.
CVE-2026-42381CRITICAL9.3Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.
CVE-2026-40798CRITICAL9.3Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.
CVE-2026-40772CRITICAL10Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.
CVE-2026-40771CRITICAL9.3Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.
CVE-2026-39591CRITICAL9.9Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.
CVE-2026-39583CRITICAL9.8Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.
CVE-2026-39530CRITICAL9.3Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.
CVE-2026-39519CRITICAL9.3Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.
CVE-2026-39512CRITICAL9.3Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.
CVE-2026-39511CRITICAL9.3Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.
CVE-2026-39502CRITICAL9.3Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.
CVE-2026-39493CRITICAL9.3Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.
CVE-2026-39492CRITICAL9.3Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.
CVE-2026-39465CRITICAL9.1Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.
CVE-2026-39441CRITICAL9.3Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.
CVE-2026-34901CRITICAL9.8Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.
CVE-2026-27053CRITICAL9.8Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.
CVE-2026-50890CRITICAL9.8Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /sto...
CVE-2026-50887CRITICAL9.1A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attac...
CVE-2026-50886CRITICAL9.1Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan inte...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now