2026 CVE Vulnerabilities

57,068 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9700HIGH7.5The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up t...
CVE-2026-57895HIGH8.5Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executa...
CVE-2026-56437HIGH8.4Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the...
CVE-2026-14500MEDIUM5.3The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and i...
CVE-2026-14495HIGH8.8The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all vers...
CVE-2026-14489HIGH8.8The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the...
CVE-2026-12153CRITICAL9.8The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1....
CVE-2026-12097MEDIUM5.3The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2...
CVE-2026-12041MEDIUM4.4The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin ...
CVE-2026-11798MEDIUM6.1The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Refle...
CVE-2026-10570MEDIUM6.4The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repea...
CVE-2026-9842HIGH7.5The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,...
CVE-2026-9701CRITICAL9.8The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and includ...
CVE-2026-14487CRITICAL9.1The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val...
CVE-2026-14482HIGH8.8The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The v...
CVE-2026-14244HIGH7.5The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu...
CVE-2026-14158HIGH8.8The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including...
CVE-2026-60002CRITICAL9.4ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This ...
CVE-2026-60001MEDIUM6.5sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CVE-2026-60000HIGH7.5sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive au...
CVE-2026-59999HIGH7.5In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not...
CVE-2026-59998MEDIUM6.5sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if th...
CVE-2026-59997MEDIUM5.4internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important ...
CVE-2026-59996MEDIUM5.4scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs betwee...
CVE-2026-59995MEDIUM5.4sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is u...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now