2026 CVE Vulnerabilities

45,449 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-2418CRITICAL9.1The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Sales...
CVE-2026-29128CRITICAL10IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zeb...
CVE-2026-29053CRITICAL9.8Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can ex...
CVE-2026-28115CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Attracti...
CVE-2026-28114CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manag...
CVE-2026-28105CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Good Energy goodenergy allows Object Injection.This issue af...
CVE-2026-28074CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Pizza House pizzahouse allows Object Injection.This issue af...
CVE-2026-28043CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27984CRITICAL9Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options ...
CVE-2026-27983CRITICAL9.8Incorrect Privilege Assignment vulnerability in designthemes LMS Elementor Pro lms-elementor-pro allows Privilege Escala...
CVE-2026-27439CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Dentario dentario allows Object Injection.This issue affects...
CVE-2026-27438CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Kingler kingler allows Object Injection.This issue affects K...
CVE-2026-27437CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Tennis Club tennis-sportclub allows Object Injection.This is...
CVE-2026-27417CRITICAL9.8Deserialization of Untrusted Data vulnerability in SeventhQueen Sweet Date sweetdate allows Object Injection.This issue ...
CVE-2026-27389CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Add...
CVE-2026-27384CRITICAL9Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Access...
CVE-2026-24960CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Charety charety allows Using Malicious Files...
CVE-2026-23802CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine ai-engine allows Using Malicious F...
CVE-2026-23767CRITICAL9.8ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and co...
CVE-2026-22501CRITICAL9.8Deserialization of Untrusted Data vulnerability in axiomthemes Mounthood mounthood allows Object Injection.This issue af...
CVE-2026-22497CRITICAL9.8Deserialization of Untrusted Data vulnerability in AncoraThemes Jardi jardi allows Object Injection.This issue affects J...
CVE-2026-22475CRITICAL9.8Deserialization of Untrusted Data vulnerability in axiomthemes Estate estate allows Object Injection.This issue affects ...
CVE-2026-22474CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Equestrian Centre equestrian-centre allows Object Injection....
CVE-2026-22454CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Solaris solaris allows Object Injection.This issue affects S...
CVE-2026-22453CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Pets Club petclub allows Object Injection.This issue affects...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now