2026 CVE Vulnerabilities

67,200 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32497MEDIUM5.3Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This is...
CVE-2026-32496MEDIUM6.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NYSL Spam Protect for Co...
CVE-2026-32495HIGH7.5Missing Authorization vulnerability in Link Software LLC WP Terms Popup wp-terms-popup allows Exploiting Incorrectly Con...
CVE-2026-32494HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Image Slid...
CVE-2026-32493HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch w...
CVE-2026-32492MEDIUM5.3Authentication Bypass by Spoofing vulnerability in Joe Dolson My Tickets my-tickets allows Identity Spoofing.This issue ...
CVE-2026-32491MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP Revie...
CVE-2026-32490MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP TripA...
CVE-2026-32489MEDIUM6.5Missing Authorization vulnerability in bPlugins B Blocks b-blocks allows Exploiting Incorrectly Configured Access Contro...
CVE-2026-32488HIGH8.1Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalatio...
CVE-2026-32485HIGH7.5Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured...
CVE-2026-32484HIGH8.8Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection.This issue affects w...
CVE-2026-32483MEDIUM6.5Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly...
CVE-2026-32482CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in deothemes Ona ona allows Upload a Web Shell to a Web Se...
CVE-2026-32441HIGH7.7Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Expl...
CVE-2026-31921HIGH8.2Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocomme...
CVE-2026-31920CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTec...
CVE-2026-31914MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hookandhook WP Cou...
CVE-2026-31913HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape sc...
CVE-2026-2995MEDIUM5.4GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.1...
CVE-2026-2973MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 1...
CVE-2026-2745HIGH8.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 1...
CVE-2026-2726MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and ...
CVE-2026-2414CRITICAL9.8Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue aff...
CVE-2026-29092HIGH7.5Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now