2026 CVE Vulnerabilities

59,282 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9626MEDIUM6.4The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the p...
CVE-2026-9180MEDIUM5.3The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key...
CVE-2026-8892MEDIUM6.4The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2026-8489MEDIUM6.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2026-14352HIGH7.5The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8...
CVE-2026-13040HIGH7.2The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2026-12557MEDIUM5.3The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc...
CVE-2026-11397MEDIUM5.5The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and in...
CVE-2026-8921HIGH8.5External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary co...
CVE-2026-12960MEDIUM6An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application o...
CVE-2026-14327HIGH7.5The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.4...
CVE-2026-12920MEDIUM4.9The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via ...
CVE-2026-12734MEDIUM6.4The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stor...
CVE-2026-12731MEDIUM6.4The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stor...
CVE-2026-12729MEDIUM4.3The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Miss...
CVE-2026-8247HIGH8.8An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local n...
CVE-2026-55726MEDIUM6.9The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious us...
CVE-2026-54477MEDIUM5.4The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.
CVE-2026-13768CRITICAL10Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub R...
CVE-2026-13728MEDIUM4.4In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved...
CVE-2026-13722HIGH7.2WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore featu...
CVE-2026-13384HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged u...
CVE-2026-13383HIGH7.2An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged ...
CVE-2026-13377MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...
CVE-2026-13376MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now