2026 CVE Vulnerabilities
67,200 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32522 | HIGH | 8.6 | 0.4% | Mar 25, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Sup... |
| CVE-2026-32521 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Northern Beaches W... |
| CVE-2026-32520 | CRITICAL | 9.8 | 0.3% | Mar 25, 2026 | Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalati... |
| CVE-2026-32519 | CRITICAL | 9 | 0.3% | Mar 25, 2026 | Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affect... |
| CVE-2026-32518 | HIGH | 7.1 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imithemes Gaea gae... |
| CVE-2026-32517 | HIGH | 7.1 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kleor Contact Mana... |
| CVE-2026-32516 | HIGH | 8.5 | 0.3% | Mar 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Mirac... |
| CVE-2026-32515 | HIGH | 7.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in kamleshyadav Miraculous miraculous allows Exploiting Incorrectly Configured Acces... |
| CVE-2026-32514 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in Anton Voytenko Petitioner petitioner allows Exploiting Incorrectly Configured Acc... |
| CVE-2026-32513 | HIGH | 8.8 | 0.3% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Objec... |
| CVE-2026-32512 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows... |
| CVE-2026-32511 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Mikado-Themes Stål stal allows Object Injection.This issue affects St... |
| CVE-2026-32510 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Edge-Themes Kamperen kamperen allows Object Injection.This issue affe... |
| CVE-2026-32509 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Edge-Themes Gracey gracey allows Object Injection.This issue affects ... |
| CVE-2026-32508 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Mikado-Themes Halstein halstein allows Object Injection.This issue af... |
| CVE-2026-32507 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Elated-Themes Leroux leroux allows Object Injection.This issue affect... |
| CVE-2026-32506 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affe... |
| CVE-2026-32505 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-32504 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-32503 | HIGH | 8.1 | 0.5% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-32502 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object ... |
| CVE-2026-32501 | HIGH | 7.1 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in wp-configurator WP Configurator Pro wp-configurator-pro allows Exploiting Incorre... |
| CVE-2026-32500 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-32499 | CRITICAL | 9.3 | 0.3% | Mar 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatB... |
| CVE-2026-32498 | HIGH | 7.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-mana... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now