2026 CVE Vulnerabilities
67,198 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4844 | HIGH | 7.3 | 0.3% | Mar 26, 2026 | A vulnerability was detected in code-projects Online Food Ordering System 1.0. This issue affects some unknown processin... |
| CVE-2026-4842 | HIGH | 7.3 | 0.3% | Mar 26, 2026 | A security vulnerability has been detected in itsourcecode Online Enrollment System 1.0. This vulnerability affects unkn... |
| CVE-2026-4841 | HIGH | 7.3 | 0.3% | Mar 26, 2026 | A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the fil... |
| CVE-2026-4840 | HIGH | 8.8 | 8.3% | Mar 26, 2026 | A security flaw has been discovered in Netcore Power 15AX up to 3.0.0.6938. Affected by this issue is the function setTo... |
| CVE-2026-4389 | MEDIUM | 6.4 | 0.2% | Mar 26, 2026 | The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2026-4331 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized data loss in all ... |
| CVE-2026-4329 | HIGH | 7.2 | 0.3% | Mar 26, 2026 | The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP hea... |
| CVE-2026-4281 | MEDIUM | 5.3 | 0.5% | Mar 26, 2026 | The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up t... |
| CVE-2026-4278 | MEDIUM | 6.4 | 0.2% | Mar 26, 2026 | The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortco... |
| CVE-2026-33201 | HIGH | 7 | 0.2% | Mar 26, 2026 | Digital Photo Frame GH-WDF10A provided by GREEN HOUSE CO., LTD. contains an active debug code vulnerability. If this vul... |
| CVE-2026-2931 | HIGH | 8.8 | 0.4% | Mar 26, 2026 | The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and includ... |
| CVE-2026-4839 | HIGH | 7.3 | 0.3% | Mar 26, 2026 | A vulnerability has been found in SourceCodester Food Ordering System 1.0. This affects an unknown function of the file ... |
| CVE-2026-4838 | HIGH | 7.3 | 0.3% | Mar 26, 2026 | A flaw has been found in SourceCodester Malawi Online Market 1.0. The impacted element is an unknown function of the fil... |
| CVE-2026-4335 | MEDIUM | 5.4 | 0.2% | Mar 26, 2026 | The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post... |
| CVE-2026-4075 | MEDIUM | 6.4 | 0.2% | Mar 26, 2026 | The BWL Advanced FAQ Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'baf_sbox' s... |
| CVE-2026-3328 | HIGH | 7.2 | 0.5% | Mar 26, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the '... |
| CVE-2026-1986 | MEDIUM | 6.1 | 0.3% | Mar 26, 2026 | The FloristPress for Woo – Customize your eCommerce store for your Florist plugin for WordPress is vulnerable to Reflect... |
| CVE-2026-4836 | MEDIUM | 6.3 | 0.2% | Mar 26, 2026 | A vulnerability was detected in code-projects Accounting System 1.0. The affected element is an unknown function of the ... |
| CVE-2026-4835 | LOW | 3.5 | 0.2% | Mar 26, 2026 | A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of th... |
| CVE-2026-4833 | LOW | 3.3 | 0.1% | Mar 26, 2026 | A weakness has been identified in Orc discount up to 3.0.1.2. This issue affects the function compile of the file markdo... |
| CVE-2026-4831 | LOW | 3.7 | 0.5% | Mar 26, 2026 | A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source... |
| CVE-2026-4484 | HIGH | 8.8 | 0.4% | Mar 26, 2026 | The Masteriyo LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.6... |
| CVE-2026-4830 | MEDIUM | 5.6 | 0.3% | Mar 26, 2026 | A vulnerability was identified in kalcaddle kodbox 1.64. This issue affects the function Add of the file app/controller/... |
| CVE-2026-33942 | CRITICAL | 9.8 | 0.6% | Mar 26, 2026 | Saloon is a PHP library that gives users tools to build API integrations and SDKs. Versions prior to 4.0.0 used PHP's un... |
| CVE-2026-33526 | HIGH | 7.5 | 8.9% | Mar 26, 2026 | Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now