2026 CVE Vulnerabilities

68,105 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30402CRITICAL9.8An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection functi...
CVE-2026-2369CRITICAL9.1A flaw was found in libsoup. An integer underflow vulnerability occurs when processing content with a zero-length resour...
CVE-2026-27043HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGoods Photography allows Path Traversal.This issue...
CVE-2026-22558HIGH7.7An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with aut...
CVE-2026-22557CRITICAL10A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network App...
CVE-2026-3658HIGH7.5The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to SQL...
CVE-2026-3511HIGH8.6Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allow...
CVE-2026-27070HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPEverest Everest ...
CVE-2026-27068HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard Websit...
CVE-2026-27067CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Syarif Mobile App Editor mobile-app-editor allows Uploa...
CVE-2026-27065CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-25445HIGH8.8Deserialization of Untrusted Data vulnerability in Membership Software WishList Member X allows Object Injection.This is...
CVE-2026-25443HIGH7.5Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-an...
CVE-2026-25442HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QantumThemes Kenth...
CVE-2026-25438HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenber...
CVE-2026-21788MEDIUM5.4HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbi...
CVE-2026-3475MEDIUM5.3The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all ver...
CVE-2026-25471HIGH8.1Authentication Bypass Using an Alternate Path or Channel vulnerability in Themepaste Admin Safety Guard admin-safety-gua...
CVE-2026-25312HIGH7.5Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incor...
CVE-2026-4120MEDIUM6.4The Info Cards – Add Text and Media in Card Layouts plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2026-4068MEDIUM4.3The Add Custom Fields to Media plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2026-4006MEDIUM6.4The Simple Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' post meta...
CVE-2026-2571MEDIUM4.3The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2026-27093HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27091MEDIUM6.3Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured Access...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now