2026 CVE Vulnerabilities

45,107 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-1359HIGH8.8The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due t...
CVE-2026-9282HIGH7.5The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4...
CVE-2026-6939HIGH7.2The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app...
CVE-2026-4661HIGH7.5The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQ...
CVE-2026-15155HIGH8.8The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authent...
CVE-2026-7655HIGH8.1The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and incl...
CVE-2026-13378HIGH7.2The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contac...
CVE-2026-3576HIGH7.2The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local ...
CVE-2026-2354HIGH8.8The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validatio...
CVE-2026-15335HIGH7.5The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in ...
CVE-2026-14262HIGH8.8The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Byp...
CVE-2026-15338HIGH7.5The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to...
CVE-2026-13353HIGH8.8The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remo...
CVE-2026-13114HIGH7.2The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2026-13756HIGH8.8The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3...
CVE-2026-55175HIGH7.5Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, a...
CVE-2026-44383HIGH8.7Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to de...
CVE-2026-42952HIGH8.7Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could al...
CVE-2026-57584HIGH8.7Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a def...
CVE-2026-55883HIGH8.3Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebS...
CVE-2026-55882HIGH8.3Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD serv...
CVE-2026-55852HIGH8.6Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Imp...
CVE-2026-55810HIGH8.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphin...
CVE-2026-55809HIGH8.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance f...
CVE-2026-54736HIGH8.2Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now