2026 CVE Vulnerabilities
67,211 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27075 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27073 | HIGH | 7.5 | 0.2% | Mar 25, 2026 | Use of Hard-coded Credentials vulnerability in Addi Addi – Cuotas que se adaptan a ti buy-now-pay-later-addi allows Pass... |
| CVE-2026-27071 | CRITICAL | 9.1 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-27054 | HIGH | 7.1 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ... |
| CVE-2026-27051 | CRITICAL | 9.8 | 0.3% | Mar 25, 2026 | Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: fro... |
| CVE-2026-27049 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobica Core jobica-core allows Authen... |
| CVE-2026-27048 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27047 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27046 | MEDIUM | 6.5 | 0.4% | Mar 25, 2026 | Missing Authorization vulnerability in Kaira StoreCustomizer woocustomizer allows Exploiting Incorrectly Configured Acce... |
| CVE-2026-27045 | HIGH | 8.8 | 0.3% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in sbthemes WooCommerce Infinite Scroll sb-woocommerce-infinite-scroll a... |
| CVE-2026-27044 | CRITICAL | 9.9 | 0.3% | Mar 25, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite all... |
| CVE-2026-27040 | HIGH | 8.8 | 0.4% | Mar 25, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AA-Team WZone woozone al... |
| CVE-2026-27039 | HIGH | 8.5 | 0.3% | Mar 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone wooz... |
| CVE-2026-26233 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to rate limit login r... |
| CVE-2026-25645 | MEDIUM | 5.5 | 0.2% | Mar 25, 2026 | Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a... |
| CVE-2026-25469 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in ViaBill for WooCommerce ViaBill – WooCommerce viabill-woocommerce allows Exploiti... |
| CVE-2026-25465 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople CP Mult... |
| CVE-2026-25464 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-25462 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in avalex avalex avalex allows Exploiting Incorrectly Configured Access Control Secu... |
| CVE-2026-25461 | HIGH | 7.1 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in purethemes Listeo ... |
| CVE-2026-25460 | MEDIUM | 6.3 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in LiquidThemes Ave Core ave-core allows Exploiting Incorrectly Configured Access Co... |
| CVE-2026-25458 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-25457 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-25456 | HIGH | 7.3 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in Aarsiv Groups Automated FedEx live/manual rates with shipping labels a2z-fedex-sh... |
| CVE-2026-25455 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Exp... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now