2026 CVE Vulnerabilities

44,054 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49006MEDIUM5.3By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmiss...
CVE-2026-19079MEDIUM4.4A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. W...
CVE-2026-16027MEDIUM5.4Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Requ...
CVE-2026-15239MEDIUM5.3The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache...
CVE-2026-15211MEDIUM5.9The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal ...
CVE-2026-15148MEDIUM5.3The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates fro...
CVE-2026-12261MEDIUM5.3A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisonin...
CVE-2026-19196HIGH7.3A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the ...
CVE-2026-16265MEDIUM6.5The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not r...
CVE-2026-16263HIGH8.8The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not p...
CVE-2026-16262HIGH7.5The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating...
CVE-2026-16258CRITICAL9.8The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing u...
CVE-2026-16041HIGH7.5The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST p...
CVE-2026-16039MEDIUM6.5The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, ...
CVE-2026-16038CRITICAL9.1The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an or...
CVE-2026-16030HIGH8.1The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used t...
CVE-2026-15386MEDIUM5.4The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an att...
CVE-2026-15361HIGH8.1The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does n...
CVE-2026-15359MEDIUM6.5The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allow...
CVE-2026-15245MEDIUM5.4The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript con...
CVE-2026-15215HIGH8.8The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing ...
CVE-2026-15214MEDIUM4.3The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription...
CVE-2026-15032MEDIUM6.1The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an...
CVE-2026-14943HIGH7.5The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 d...
CVE-2026-14331MEDIUM6.1The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now