2026 CVE Vulnerabilities

61,122 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-55740CRITICAL9.8Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthe...
CVE-2026-12120MEDIUM5.3The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information...
CVE-2026-12093MEDIUM5.3The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4...
CVE-2026-11784MEDIUM4.3The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vuln...
CVE-2026-11777MEDIUM4.9The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic...
CVE-2026-11776MEDIUM4.9The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic...
CVE-2026-11402MEDIUM6.4The Services Section Block – Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cr...
CVE-2026-11360MEDIUM4.9The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_dire...
CVE-2026-11358MEDIUM4.4The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulne...
CVE-2026-11357MEDIUM4.3The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Informati...
CVE-2026-10736MEDIUM4.9The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the...
CVE-2026-10623MEDIUM4.3The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecur...
CVE-2026-10029MEDIUM5.3The Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitiv...
CVE-2026-12505HIGH7.8A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges befor...
CVE-2026-12407HIGH8.8The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to,...
CVE-2026-10023MEDIUM4.3The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr...
CVE-2026-12569CRITICAL9.8A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vul...
CVE-2026-48768CRITICAL9.3TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is...
CVE-2026-48764HIGH8.2TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname o...
CVE-2026-54533MEDIUM6.9vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms ...
CVE-2026-54445MEDIUM6.9vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial us...
CVE-2026-53676HIGH8.6ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed c...
CVE-2026-50268LOW1.9Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50267MEDIUM4.7Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50202MEDIUM5.9Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now