2026 CVE Vulnerabilities

67,237 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3225MEDIUM4.3The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized deletion of quiz question answe...
CVE-2026-33168LOW2.3Action View provides conventions and helpers for building web pages with the Rails framework. Prior to versions 8.1.2.1,...
CVE-2026-33167MEDIUM6.1Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8....
CVE-2026-33046HIGH8.8Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In vers...
CVE-2026-2412MEDIUM6.5The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter...
CVE-2026-4681CRITICAL9.3A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerabili...
CVE-2026-4612HIGH7.3A vulnerability has been found in itsourcecode Free Hotel Reservation System 1.0. This affects an unknown part of the fi...
CVE-2026-4611HIGH8.8A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the fu...
CVE-2026-33634HIGH8.8Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy...
CVE-2026-32913CRITICAL9.1OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom...
CVE-2026-32912——Rejected reason: This CVE ID has been rejected.
CVE-2026-32911——Rejected reason: This CVE ID has been rejected.
CVE-2026-32910——Rejected reason: This CVE ID has been rejected.
CVE-2026-32909——Rejected reason: This CVE ID has been rejected.
CVE-2026-32908——Rejected reason: This CVE ID has been rejected.
CVE-2026-32907——Rejected reason: This CVE ID has been rejected.
CVE-2026-32904——Rejected reason: This CVE ID has been rejected.
CVE-2026-32903——Rejected reason: This CVE ID has been rejected.
CVE-2026-32902——Rejected reason: This CVE ID has been rejected.
CVE-2026-32901——Rejected reason: This CVE ID has been rejected.
CVE-2026-32900——Rejected reason: This CVE ID has been rejected.
CVE-2026-32300HIGH8.1Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the...
CVE-2026-32299HIGH7.5Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the...
CVE-2026-32279MEDIUM6.8Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the...
CVE-2026-32278MEDIUM4.8Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now