2026 CVE Vulnerabilities
67,211 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32441 | HIGH | 7.7 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in WebToffee Comments Import & Export comments-import-export-woocommerce allows Expl... |
| CVE-2026-31921 | HIGH | 8.2 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocomme... |
| CVE-2026-31920 | CRITICAL | 9.3 | 0.3% | Mar 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTec... |
| CVE-2026-31914 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hookandhook WP Cou... |
| CVE-2026-31913 | HIGH | 8.6 | 0.4% | Mar 25, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape sc... |
| CVE-2026-2995 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.1... |
| CVE-2026-2973 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 1... |
| CVE-2026-2745 | HIGH | 8.1 | 0.3% | Mar 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 1... |
| CVE-2026-2726 | MEDIUM | 4.3 | 0.2% | Mar 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and ... |
| CVE-2026-2414 | CRITICAL | 9.8 | 0.3% | Mar 25, 2026 | Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue aff... |
| CVE-2026-29092 | HIGH | 7.5 | 0.2% | Mar 25, 2026 | Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway... |
| CVE-2026-27659 | MEDIUM | 4.6 | 0.1% | Mar 25, 2026 | Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to properly validate ... |
| CVE-2026-27656 | MEDIUM | 6.1 | 0.2% | Mar 25, 2026 | Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate ... |
| CVE-2026-27095 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-bo... |
| CVE-2026-27088 | HIGH | 7.1 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Darna Fram... |
| CVE-2026-27087 | HIGH | 7.1 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Wolverine ... |
| CVE-2026-27084 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects B... |
| CVE-2026-27083 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Inje... |
| CVE-2026-27082 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affe... |
| CVE-2026-27081 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27080 | HIGH | 8.1 | 0.5% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27079 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27078 | HIGH | 8.1 | 0.5% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27077 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27076 | HIGH | 8.1 | 0.5% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now