2026 CVE Vulnerabilities
67,418 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25443 | HIGH | 7.5 | 0.2% | Mar 19, 2026 | Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-an... |
| CVE-2026-25442 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes Kenth... |
| CVE-2026-25438 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenber... |
| CVE-2026-21788 | MEDIUM | 5.4 | 0.2% | Mar 19, 2026 | HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbi... |
| CVE-2026-3475 | MEDIUM | 5.3 | 0.3% | Mar 19, 2026 | The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all ver... |
| CVE-2026-25471 | HIGH | 8.1 | 0.3% | Mar 19, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themepaste Admin Safety Guard admin-safety-gua... |
| CVE-2026-25312 | HIGH | 7.5 | 0.2% | Mar 19, 2026 | Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incor... |
| CVE-2026-4120 | MEDIUM | 6.4 | 0.2% | Mar 19, 2026 | The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2026-4068 | MEDIUM | 4.3 | 0.1% | Mar 19, 2026 | The Add Custom Fields to Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2026-4006 | MEDIUM | 6.4 | 0.3% | Mar 19, 2026 | The Simple Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' post meta... |
| CVE-2026-2571 | MEDIUM | 4.3 | 0.2% | Mar 19, 2026 | The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2026-27093 | HIGH | 8.1 | 0.3% | Mar 19, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27091 | MEDIUM | 6.3 | 0.2% | Mar 19, 2026 | Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured Access... |
| CVE-2026-28073 | HIGH | 7.1 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tips and Tricks HQ... |
| CVE-2026-28070 | MEDIUM | 5.3 | 0.3% | Mar 19, 2026 | Missing Authorization vulnerability in Tips and Tricks HQ WP eMember allows Exploiting Incorrectly Configured Access Con... |
| CVE-2026-28044 | MEDIUM | 5.9 | 0.1% | Mar 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media WP Rocket... |
| CVE-2026-27542 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wh... |
| CVE-2026-27540 | CRITICAL | 9 | 0.5% | Mar 19, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Captu... |
| CVE-2026-27413 | CRITICAL | 9.3 | 0.4% | Mar 19, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile... |
| CVE-2026-27397 | MEDIUM | 6.5 | 0.2% | Mar 19, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Really Simple Plugins B.V. Really Simple Security Pro ... |
| CVE-2026-27096 | HIGH | 8.1 | 0.3% | Mar 19, 2026 | Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio - Freelance Designer WordPress Theme allows O... |
| CVE-2026-1238 | HIGH | 7.2 | 0.3% | Mar 19, 2026 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) para... |
| CVE-2026-1276 | MEDIUM | 5.4 | 0.1% | Mar 19, 2026 | IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This vulnerability allows a... |
| CVE-2026-32000 | HIGH | 7.1 | 0.6% | Mar 19, 2026 | OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution t... |
| CVE-2026-31999 | HIGH | 7.8 | 0.2% | Mar 19, 2026 | OpenClaw versions 2026.2.26 prior to 2026.3.1 on Windows contain a current working directory injection vulnerability in ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now