2026 CVE Vulnerabilities
69,542 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1708 | HIGH | 7.5 | 0.4% | Mar 11, 2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to bli... |
| CVE-2026-3826 | CRITICAL | 9.8 | 0.5% | Mar 11, 2026 | IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to exe... |
| CVE-2026-3825 | MEDIUM | 6.1 | 0.3% | Mar 11, 2026 | IFTOP developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attacker... |
| CVE-2026-3824 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL... |
| CVE-2026-3534 | MEDIUM | 6.4 | 0.2% | Mar 11, 2026 | The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-c... |
| CVE-2026-31844 | HIGH | 8.8 | 0.4% | Mar 11, 2026 | An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion... |
| CVE-2026-3911 | LOW | 2.7 | 0.3% | Mar 11, 2026 | A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserRe... |
| CVE-2026-3884 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that a... |
| CVE-2026-3222 | HIGH | 7.5 | 0.4% | Mar 11, 2026 | The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all ... |
| CVE-2026-2707 | MEDIUM | 6.4 | 0.2% | Mar 11, 2026 | The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API entry submission endpoint... |
| CVE-2026-2631 | CRITICAL | 9.8 | 0.6% | Mar 11, 2026 | The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows a... |
| CVE-2026-2626 | HIGH | 8.1 | 0.2% | Mar 11, 2026 | The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function... |
| CVE-2026-2466 | HIGH | 7.1 | 0.1% | Mar 11, 2026 | The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2026-2358 | MEDIUM | 6.4 | 0.2% | Mar 11, 2026 | The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[wp_ulike_likers_box]` shortcode... |
| CVE-2026-27842 | CRITICAL | 9.8 | 0.6% | Mar 11, 2026 | Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication an... |
| CVE-2026-24448 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administr... |
| CVE-2026-20892 | HIGH | 8.6 | 0.6% | Mar 11, 2026 | Code injection vulnerability exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker with administrative privil... |
| CVE-2026-1867 | MEDIUM | 5.9 | 0.2% | Mar 11, 2026 | The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to reg... |
| CVE-2026-1753 | MEDIUM | 6.8 | 0.2% | Mar 11, 2026 | The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors a... |
| CVE-2026-2413 | HIGH | 7.5 | 2.3% | Mar 11, 2026 | The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all ver... |
| CVE-2026-29515 | CRITICAL | 9.8 | 0.5% | Mar 11, 2026 | MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that all... |
| CVE-2026-23817 | MEDIUM | 6.1 | 0.3% | Mar 11, 2026 | A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker ... |
| CVE-2026-23816 | HIGH | 8.8 | 0.7% | Mar 11, 2026 | A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute... |
| CVE-2026-23815 | HIGH | 7.2 | 0.9% | Mar 11, 2026 | A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high p... |
| CVE-2026-23814 | HIGH | 8.8 | 0.6% | Mar 11, 2026 | A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now