2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44411HIGH7.8A vulnerability has been identified in Solid Edge SE2026 (All versions < V226.0 Update 5). The affected application is v...
CVE-2026-41551CRITICAL9.3A vulnerability has been identified in ROS# (All versions < V2.2.2). Affected versions contain a path traversal vulnerab...
CVE-2026-41125MEDIUM6A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions), blu...
CVE-2026-33893HIGH8.7A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2...
CVE-2026-33862MEDIUM6.1A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2...
CVE-2026-27662HIGH7.7Affected devices do not properly restrict access to the web browser via the Control Panel when no corresponding security...
CVE-2026-25789HIGH7.2Affected devices do not properly validate and sanitize filenames on the Firmware Update page. This could allow a remote ...
CVE-2026-25787CRITICAL9.3Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagn...
CVE-2026-25786CRITICAL9.3Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page ...
CVE-2026-22925HIGH8.7A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application is susceptible to...
CVE-2026-22924CRITICAL9.1A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly...
CVE-2026-1934MEDIUM4.3The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user...
CVE-2026-7661MEDIUM6.4The Bootstrap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `box` shortcode in all...
CVE-2026-7659MEDIUM6.4The Advanced Social Media Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `social` short...
CVE-2026-7626MEDIUM5.3The Slek Gateway for WooCommerce plugin for WordPress is vulnerable to Information Exposure in version 1.0. This is due ...
CVE-2026-7616MEDIUM4.3The Zawgyi Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2026-7562MEDIUM4.3The WP-Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including ...
CVE-2026-7561MEDIUM6.1The Tm – WordPress Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2026-7464MEDIUM6.1The WP Google Maps Integration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` param...
CVE-2026-7437MEDIUM6.1The AzonPost plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `editpos_hidden` parameter in ...
CVE-2026-7050MEDIUM4.3The Forms Rb plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.9. Thi...
CVE-2026-6932MEDIUM4.3The Woo Commerce Minimum Weight plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to a...
CVE-2026-6913MEDIUM6.4The Shortcodely plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'widget_area' parameter in all...
CVE-2026-6808MEDIUM6.1The Pricing Tables for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter ...
CVE-2026-6710MEDIUM4.3The Skysa Text Ticker App plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now