2026 CVE Vulnerabilities

64,848 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-2948MEDIUM6.4The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Server-Side Requ...
CVE-2026-6704MEDIUM6.1The Blog Settings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all v...
CVE-2026-6702MEDIUM6.1The Publish 2 Ping.fm plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2026-6701MEDIUM4.3The addfreespace plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2026-6700MEDIUM4.3The DX Sources plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2....
CVE-2026-6696MEDIUM6.1The Zingaya Click-to-Call plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email', 'first_n...
CVE-2026-6255MEDIUM6.4The Simple Owl Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'num' attribute of t...
CVE-2026-5505MEDIUM6.4The WP-Clippy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `clippy` shortcode in a...
CVE-2026-5247MEDIUM5.5The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2026-5100HIGH7.5The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versio...
CVE-2026-4730MEDIUM6.4The Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website plugin for WordPress is vulnerabl...
CVE-2026-4409MEDIUM6.5The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leak...
CVE-2026-2868MEDIUM6.4The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Sit...
CVE-2026-1921MEDIUM4.9The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.8.2 via ...
CVE-2026-5722CRITICAL9.8The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1....
CVE-2026-44029MEDIUM5.3An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "n...
CVE-2026-44028HIGH7.5An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser ...
CVE-2026-7788HIGH7.3A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. The af...
CVE-2026-7785HIGH7.3A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f2...
CVE-2026-7784HIGH7.3A vulnerability has been found in RTGS2017 NagaAgent up to 5.1.0. This issue affects some unknown processing of the file...
CVE-2026-7783MEDIUM6.3A flaw has been found in CodeCanyon Perfex CRM up to 3.4.1. This vulnerability affects the function AbstractKanban::appl...
CVE-2026-7782MEDIUM6.3A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the fil...
CVE-2026-7781MEDIUM4.3A security vulnerability has been detected in Open5GS up to 2.7.7. Affected by this issue is the function udm_nudm_uecm_...
CVE-2026-7791HIGH8.5Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpace...
CVE-2026-7780MEDIUM4.3A weakness has been identified in Open5GS up to 2.7.7. Affected by this vulnerability is the function udm_state_operatio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now