2026 CVE Vulnerabilities

67,198 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4844HIGH7.3A vulnerability was detected in code-projects Online Food Ordering System 1.0. This issue affects some unknown processin...
CVE-2026-4842HIGH7.3A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. This vulnerability affects unkn...
CVE-2026-4841HIGH7.3A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the fil...
CVE-2026-4840HIGH8.8A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTo...
CVE-2026-4389MEDIUM6.4The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-4331MEDIUM4.3The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized data loss in all ...
CVE-2026-4329HIGH7.2The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP hea...
CVE-2026-4281MEDIUM5.3The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up t...
CVE-2026-4278MEDIUM6.4The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortco...
CVE-2026-33201HIGH7Digital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., LTD. contains an active debug code vulnerability. If this vul...
CVE-2026-2931HIGH8.8The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and includ...
CVE-2026-4839HIGH7.3A vulnerability has been found in SourceCodester Food Ordering System 1.0. This affects an unknown function of the file ...
CVE-2026-4838HIGH7.3A flaw has been found in SourceCodester Malawi Online Market 1.0. The impacted element is an unknown function of the fil...
CVE-2026-4335MEDIUM5.4The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post...
CVE-2026-4075MEDIUM6.4The BWL Advanced FAQ Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'baf_sbox' s...
CVE-2026-3328HIGH7.2The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the '...
CVE-2026-1986MEDIUM6.1The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflect...
CVE-2026-4836MEDIUM6.3A vulnerability was detected in code-projects Accounting System 1.0. The affected element is an unknown function of the ...
CVE-2026-4835LOW3.5A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of th...
CVE-2026-4833LOW3.3A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdo...
CVE-2026-4831LOW3.7A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source...
CVE-2026-4484HIGH8.8The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6...
CVE-2026-4830MEDIUM5.6A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/...
CVE-2026-33942CRITICAL9.8Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's un...
CVE-2026-33526HIGH7.5Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now