2026 CVE Vulnerabilities

64,716 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7284CRITICAL9.8The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation ...
CVE-2026-6555CRITICAL9.8The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, ...
CVE-2026-6549MEDIUM6.4The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute ...
CVE-2026-6456HIGH8.8The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1....
CVE-2026-6452MEDIUM4.3The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2026-6404MEDIUM4.4The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2026-6401MEDIUM4.3The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.1....
CVE-2026-6400MEDIUM4.3The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2026-6399MEDIUM4.4The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1....
CVE-2026-6397MEDIUM6.4The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmorete...
CVE-2026-6395MEDIUM6.1The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting ...
CVE-2026-6394MEDIUM5.4The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server...
CVE-2026-6391MEDIUM6.1The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-6072MEDIUM6.5The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through Us...
CVE-2026-5293MEDIUM6.4The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js'...
CVE-2026-45232LOW3.7Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connect...
CVE-2026-43620MEDIUM5.5Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver...
CVE-2026-43619HIGH7.2Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod,...
CVE-2026-43618HIGH8.1Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit s...
CVE-2026-43617MEDIUM6.3Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access ...
CVE-2026-3985HIGH7.5The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection v...
CVE-2026-45585MEDIUM6.8Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". ...
CVE-2026-39309MEDIUM5.5Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas...
CVE-2026-35593MEDIUM6.8Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowled...
CVE-2026-34970MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to acces...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now