2026 CVE Vulnerabilities

66,316 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5531MEDIUM5.5A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function o...
CVE-2026-5530MEDIUM6.3A flaw has been found in Ollama up to 0.18.1. This issue affects some unknown processing of the file server/download.go ...
CVE-2026-5529MEDIUM4.3A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the ...
CVE-2026-5528MEDIUM6.3A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown par...
CVE-2026-5527MEDIUM5.5A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown fu...
CVE-2026-5526CRITICAL9.8A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerabil...
CVE-2026-3666HIGH8.8The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4...
CVE-2026-3309MEDIUM6.5The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2026-2936HIGH7.2The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page...
CVE-2026-1233HIGH7.5The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure i...
CVE-2026-0626MEDIUM6.4The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulner...
CVE-2026-5425HIGH7.2The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' ...
CVE-2026-3445HIGH7.1The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2026-2826MEDIUM4.3The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypas...
CVE-2026-2437MEDIUM6.4The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-4896HIGH8.1The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is...
CVE-2026-2600MEDIUM6.4The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2026-0738MEDIUM6.4The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2026-0737MEDIUM6.4The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ...
CVE-2026-0664MEDIUM6.4The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' p...
CVE-2026-0552MEDIUM6.4The Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsc_displa...
CVE-2026-2949MEDIUM6.4The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the I...
CVE-2026-2924MEDIUM6.4The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Sit...
CVE-2026-3571MEDIUM6.5The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized ...
CVE-2026-35616CRITICAL9.8A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now