2026 CVE Vulnerabilities
67,213 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25456 | HIGH | 7.3 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in Aarsiv Groups Automated FedEx live/manual rates with shipping labels a2z-fedex-sh... |
| CVE-2026-25455 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Exp... |
| CVE-2026-25454 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in MVPThemes The League the-league allows Exploiting Incorrectly Configured Access C... |
| CVE-2026-25452 | HIGH | 7.1 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDO Remoji remoji... |
| CVE-2026-25447 | CRITICAL | 9.1 | 0.3% | Mar 25, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wr... |
| CVE-2026-25437 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in سید محمدامین هاشمی GZSEO gzseo allows Exploiting Incorrectly Configured Access Co... |
| CVE-2026-25435 | HIGH | 7.1 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevart Booking c... |
| CVE-2026-25430 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in CRM Perks Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja... |
| CVE-2026-25429 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue aff... |
| CVE-2026-25417 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileG... |
| CVE-2026-25414 | HIGH | 8.8 | 0.3% | Mar 25, 2026 | Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation.This ... |
| CVE-2026-25413 | CRITICAL | 9.9 | 0.3% | Mar 25, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Mal... |
| CVE-2026-25406 | HIGH | 8.1 | 0.3% | Mar 25, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authent... |
| CVE-2026-25401 | HIGH | 7.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in Arni Cinco WPCargo Track & Trace wpcargo allows Exploiting Incorrectly Configured... |
| CVE-2026-25400 | HIGH | 8.8 | 0.3% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection.This issue affects... |
| CVE-2026-25398 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in Webilia Inc. Vertex Addons for Elementor addons-for-elementor-builder allows Expl... |
| CVE-2026-25397 | HIGH | 7.5 | 0.4% | Mar 25, 2026 | Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerc... |
| CVE-2026-25396 | HIGH | 7.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in CoderPress Commerce Coinbase For WooCommerce commerce-coinbase-for-woocommerce al... |
| CVE-2026-25390 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Config... |
| CVE-2026-25383 | HIGH | 7.1 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iqonic Design Kivi... |
| CVE-2026-25382 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-25381 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-25380 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-25379 | HIGH | 8.1 | 0.4% | Mar 25, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-25377 | CRITICAL | 9.3 | 0.3% | Mar 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobse... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now