2026 CVE Vulnerabilities
45,207 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32512 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows... |
| CVE-2026-32502 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object ... |
| CVE-2026-32499 | CRITICAL | 9.3 | 0.3% | Mar 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatB... |
| CVE-2026-32482 | CRITICAL | 9.9 | 0.3% | Mar 25, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in deothemes Ona ona allows Upload a Web Shell to a Web Se... |
| CVE-2026-31920 | CRITICAL | 9.3 | 0.3% | Mar 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTec... |
| CVE-2026-2414 | CRITICAL | 9.8 | 0.3% | Mar 25, 2026 | Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue aff... |
| CVE-2026-27095 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-bo... |
| CVE-2026-27084 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects B... |
| CVE-2026-27083 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Inje... |
| CVE-2026-27082 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affe... |
| CVE-2026-27071 | CRITICAL | 9.1 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-27051 | CRITICAL | 9.8 | 0.3% | Mar 25, 2026 | Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: fro... |
| CVE-2026-27049 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobica Core jobica-core allows Authen... |
| CVE-2026-27044 | CRITICAL | 9.9 | 0.3% | Mar 25, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite all... |
| CVE-2026-25447 | CRITICAL | 9.1 | 0.3% | Mar 25, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wr... |
| CVE-2026-25429 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue aff... |
| CVE-2026-25413 | CRITICAL | 9.9 | 0.3% | Mar 25, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Mal... |
| CVE-2026-25377 | CRITICAL | 9.3 | 0.3% | Mar 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobse... |
| CVE-2026-25371 | CRITICAL | 9.3 | 0.3% | Mar 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in King-Theme Lumise ... |
| CVE-2026-25366 | CRITICAL | 9.9 | 0.3% | Mar 25, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows... |
| CVE-2026-25345 | CRITICAL | 9.9 | 0.4% | Mar 25, 2026 | Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block a... |
| CVE-2026-25340 | CRITICAL | 9.3 | 0.3% | Mar 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Jobmonste... |
| CVE-2026-25035 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Co... |
| CVE-2026-25032 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects ... |
| CVE-2026-25031 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This iss... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now