2026 CVE Vulnerabilities

64,616 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40826MEDIUM6.9A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dsgvo_contracts view...
CVE-2026-40825HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view d...
CVE-2026-40824HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view u...
CVE-2026-40823HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct...
CVE-2026-40822MEDIUM6.9A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct...
CVE-2026-40821MEDIUM6.9A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountByID funct...
CVE-2026-40819HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task du...
CVE-2026-40818HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24confi_getDevic...
CVE-2026-40817HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAlarmProfiles fu...
CVE-2026-40816HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the mb24alarm.php files...
CVE-2026-40815HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24api_getUserAcc...
CVE-2026-40814HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dataapi.php files _...
CVE-2026-40813HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues funct...
CVE-2026-40812HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues funct...
CVE-2026-40811HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractservice ...
CVE-2026-40810HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endpoint d...
CVE-2026-3897MEDIUM6.4The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_a...
CVE-2026-3896MEDIUM6.4The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_aj...
CVE-2026-3895MEDIUM6.4The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `...
CVE-2026-3375HIGH7.2The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/noti...
CVE-2026-3279MEDIUM6.5The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2026-3001MEDIUM6.1The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all version...
CVE-2026-2030MEDIUM6.4The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `...
CVE-2026-9200HIGH7.5The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2...
CVE-2026-9014MEDIUM5.3The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now