2026 CVE Vulnerabilities

44,969 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-19335MEDIUM5.3A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function ...
CVE-2026-18603MEDIUM6.5The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ...
CVE-2026-18473CRITICAL9.1The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in ...
CVE-2026-18465MEDIUM6.5The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a...
CVE-2026-18464HIGH7.5The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a...
CVE-2026-18357HIGH7.5The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of...
CVE-2026-18037MEDIUM6.5The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of it...
CVE-2026-18032HIGH7.5The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthent...
CVE-2026-17044HIGH8.6The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it ...
CVE-2026-17017HIGH8.1The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in...
CVE-2026-17014MEDIUM5.3The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its ...
CVE-2026-17011LOW3.8The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpo...
CVE-2026-16992MEDIUM6.5The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of it...
CVE-2026-16988HIGH7.5The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker dat...
CVE-2026-16965MEDIUM4.3The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, a...
CVE-2026-16957LOW2.7The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed ...
CVE-2026-16032MEDIUM6.1The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated an...
CVE-2026-15038CRITICAL9.8The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenti...
CVE-2026-19334MEDIUM5.3A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown pa...
CVE-2026-19333MEDIUM5.3A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a...
CVE-2026-19332MEDIUM5.3A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functi...
CVE-2026-19331MEDIUM5.3A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanva...
CVE-2026-19330MEDIUM5.3A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_s...
CVE-2026-19329MEDIUM5.3A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element i...
CVE-2026-10595HIGH7.5A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemen...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now