2026 CVE Vulnerabilities

69,542 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-1708HIGH7.5The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to bli...
CVE-2026-3826CRITICAL9.8IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to exe...
CVE-2026-3825MEDIUM6.1IFTOP developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attacker...
CVE-2026-3824MEDIUM6.1IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL...
CVE-2026-3534MEDIUM6.4The Astra theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `ast-page-background-meta` and `ast-c...
CVE-2026-31844HIGH8.8An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion...
CVE-2026-3911LOW2.7A flaw was found in Keycloak. An authenticated user with the view-users role could exploit a vulnerability in the UserRe...
CVE-2026-3884MEDIUM6.1Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that a...
CVE-2026-3222HIGH7.5The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all ...
CVE-2026-2707MEDIUM6.4The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API entry submission endpoint...
CVE-2026-2631CRITICAL9.8The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows a...
CVE-2026-2626HIGH8.1The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function...
CVE-2026-2466HIGH7.1The DukaPress WordPress plugin through 3.2.4 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2026-2358MEDIUM6.4The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[wp_ulike_likers_box]` shortcode...
CVE-2026-27842CRITICAL9.8Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication an...
CVE-2026-24448CRITICAL9.8Use of hard-coded credentials issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to obtain administr...
CVE-2026-20892HIGH8.6Code injection vulnerability exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker with administrative privil...
CVE-2026-1867MEDIUM5.9The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.6 allows passing a URL parameter to reg...
CVE-2026-1753MEDIUM6.8The Gutena Forms WordPress plugin before 1.6.1 does not validate option to be updated, which could allow contributors a...
CVE-2026-2413HIGH7.5The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all ver...
CVE-2026-29515CRITICAL9.8MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that all...
CVE-2026-23817MEDIUM6.1A vulnerability in the web-based management interface of AOS-CX Switches could allow an unauthenticated remote attacker ...
CVE-2026-23816HIGH8.8A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute...
CVE-2026-23815HIGH7.2A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high p...
CVE-2026-23814HIGH8.8A vulnerability in the command parameters of a certain AOS-CX CLI command could allow a low-privilege authenticated remo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now