2026 CVE Vulnerabilities

68,868 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4063MEDIUM4.3The Social Icons Widget & Block by WPZOOM plugin for WordPress is vulnerable to unauthorized data modification due to a ...
CVE-2026-3999HIGH8.8A broken access control may allow an authenticated user to perform a horizontal privilege escalation. The vulnerability...
CVE-2026-3986MEDIUM6.4The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form settings in al...
CVE-2026-3910HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrar...
CVE-2026-3909HIGH8.8Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds m...
CVE-2026-3891CRITICAL9.8The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and...
CVE-2026-3873HIGH7.2Use of Hard-coded Credentials vulnerability in Avantra allows Accessing Functionality Not Properly Constrained by ACLs....
CVE-2026-3045HIGH7.5The Appointment Booking Calendar — Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized acces...
CVE-2026-32746CRITICAL9.8telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption ...
CVE-2026-32745MEDIUM5.7In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings
CVE-2026-32612MEDIUM5.4Statamic is a Laravel and Git powered content management system (CMS). Prior to 6.6.2, stored XSS in the control panel c...
CVE-2026-32598MEDIUM6.5OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the ...
CVE-2026-32597HIGH7.5PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header ...
CVE-2026-32543MEDIUM5.3Missing Authorization vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows Exploiting In...
CVE-2026-32487MEDIUM5.3Missing Authorization vulnerability in raratheme Lawyer Landing Page lawyer-landing-page allows Exploiting Incorrectly C...
CVE-2026-32486MEDIUM5.3Missing Authorization vulnerability in wptravelengine Travel Booking travel-booking allows Exploiting Incorrectly Config...
CVE-2026-32462MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Maste...
CVE-2026-32461MEDIUM4.3Missing Authorization vulnerability in Really Simple Plugins Really Simple SSL really-simple-ssl allows Exploiting Incor...
CVE-2026-32460MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Ultimate ...
CVE-2026-32459HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in flycart UpsellWP c...
CVE-2026-32458HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 WOLF bu...
CVE-2026-32457MEDIUM5.3Missing Authorization vulnerability in Wombat Plugins Advanced Product Fields (Product Addons) for WooCommerce advanced-...
CVE-2026-32456MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Janis Elsts Admin Menu Editor admin-menu-editor allows Cross Site Req...
CVE-2026-32455MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 MDTF wp...
CVE-2026-32454MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Avada ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now