2026 CVE Vulnerabilities

60,149 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-57234LOW2.6Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse opti...
CVE-2026-49319MEDIUM6.9Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., L...
CVE-2026-46735HIGH7.8Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Ele...
CVE-2026-13314LOW2Malicious HTML content could be injected into the content rendered by the pretix-digital plugin.
CVE-2026-13225MEDIUM5.3Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization o...
CVE-2026-13223MEDIUM6.3Our payment integration with Computop-based payment methods did not properly validate payment status responses. An atta...
CVE-2026-13222MEDIUM6.3Our payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacke...
CVE-2026-57619MEDIUM6.5Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
CVE-2026-57429MEDIUM6.5Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.
CVE-2026-56122HIGH8.7Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to ...
CVE-2026-56071HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.
CVE-2026-56054HIGH7.7Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
CVE-2026-56053HIGH8.8Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.
CVE-2026-56051HIGH7.1Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.
CVE-2026-56050MEDIUM6.5Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access ...
CVE-2026-56049HIGH8.5Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.
CVE-2026-56042HIGH7.1Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.
CVE-2026-56023MEDIUM5.4Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.
CVE-2026-56014HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.
CVE-2026-56013MEDIUM6.5Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
CVE-2026-56006HIGH7.1Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.
CVE-2026-56005HIGH7.1Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.
CVE-2026-54849CRITICAL9.3Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.
CVE-2026-54848HIGH8.3Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows R...
CVE-2026-54845HIGH8.1Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now