2026 CVE Vulnerabilities

60,340 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-11360MEDIUM4.9The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_dire...
CVE-2026-11358MEDIUM4.4The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulne...
CVE-2026-11357MEDIUM4.3The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Informati...
CVE-2026-10736MEDIUM4.9The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the...
CVE-2026-10623MEDIUM4.3The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecur...
CVE-2026-10029MEDIUM5.3The Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitiv...
CVE-2026-12505HIGH7.8A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges befor...
CVE-2026-12407HIGH8.8The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to,...
CVE-2026-10023MEDIUM4.3The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr...
CVE-2026-12569CRITICAL9.8A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vul...
CVE-2026-48768CRITICAL9.3TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is...
CVE-2026-48764HIGH8.2TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname o...
CVE-2026-54533MEDIUM6.9vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms ...
CVE-2026-54445MEDIUM6.9vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial us...
CVE-2026-53676HIGH8.6ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed c...
CVE-2026-50268LOW1.9Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50267MEDIUM4.7Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50202MEDIUM5.9Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50201MEDIUM6.5Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-48759HIGH7.1TypeBot is a chatbot builder tool. Versions 3.15.2 and below have an Insecure Direct Object Reference vulnerability thro...
CVE-2026-45617HIGH7.5LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,...
CVE-2026-45357HIGH7.5LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,...
CVE-2026-44646MEDIUM5.3LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,...
CVE-2026-44645MEDIUM6.5LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,...
CVE-2026-44644MEDIUM6.1LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. Versions 10.25.7 and below are...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now