2026 CVE Vulnerabilities

64,858 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7612MEDIUM4.7A vulnerability was determined in itsourcecode Courier Management System 1.0. Affected is an unknown function of the fil...
CVE-2026-7611HIGH8.1A vulnerability was found in TRENDnet TEW-821DAP up to 1.12B01. This impacts the function platform_do_upgrade_cameo_dev ...
CVE-2026-7610HIGH8.1A vulnerability has been found in TRENDnet TEW-821DAP 1.12B01. This affects an unknown function of the file /www/cgi/ssi...
CVE-2026-7609HIGH8.8A flaw has been found in TRENDnet TEW-821DAP up to 1.12B01. The impacted element is the function tools_diagnostic of the...
CVE-2026-7491HIGH8.6School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote att...
CVE-2026-7490HIGH7.2CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to up...
CVE-2026-7489HIGH8.8CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary ...
CVE-2026-5077MEDIUM5.4The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and includ...
CVE-2026-7608HIGH8A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic...
CVE-2026-5324HIGH7.2The Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versio...
CVE-2026-4024MEDIUM5.3The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2026-7649HIGH7.5The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is...
CVE-2026-7607HIGH8.8A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function auto_update_firmware...
CVE-2026-7606HIGH8.1A weakness has been identified in TRENDnet TEW-821DAP 1.12B01. This issue affects the function find_hwid/new_gui_update_...
CVE-2026-6457MEDIUM6.5The Geo Mashup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geo_mashup_null_fields' par...
CVE-2026-6449MEDIUM5.3The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization i...
CVE-2026-6229HIGH7.2The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and incl...
CVE-2026-4650MEDIUM5.3The FundPress – WordPress Donation Plugin for WordPress is vulnerable to authorization bypass in versions up to and incl...
CVE-2026-2052HIGH8.8The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vuln...
CVE-2026-7605MEDIUM6.3A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.u...
CVE-2026-43058MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix pass-by-value structs causing MSA...
CVE-2026-7647HIGH8.1The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3...
CVE-2026-7049HIGH7.2The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery...
CVE-2026-6916MEDIUM6.4The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul...
CVE-2026-6812MEDIUM4.4The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now