2026 CVE Vulnerabilities
69,870 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30247 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.... |
| CVE-2026-3352 | HIGH | 7.2 | 0.4% | Mar 7, 2026 | The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0... |
| CVE-2026-2722 | MEDIUM | 4.8 | 0.2% | Mar 7, 2026 | The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up... |
| CVE-2026-2721 | MEDIUM | 4.8 | 0.2% | Mar 7, 2026 | The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up... |
| CVE-2026-2494 | MEDIUM | 4.3 | 0.1% | Mar 7, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery... |
| CVE-2026-2488 | MEDIUM | 4.3 | 0.2% | Mar 7, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message delet... |
| CVE-2026-2431 | MEDIUM | 6.1 | 0.2% | Mar 7, 2026 | The CM Custom Reports plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'date_from' and 'date... |
| CVE-2026-2429 | MEDIUM | 4.9 | 0.3% | Mar 7, 2026 | The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'ce_venue_name' CSV field in the `on_sa... |
| CVE-2026-2020 | HIGH | 7.5 | 0.4% | Mar 7, 2026 | The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1... |
| CVE-2026-1902 | MEDIUM | 6.4 | 0.2% | Mar 7, 2026 | The Hammas Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'apix' parameter in the 'h... |
| CVE-2026-1650 | MEDIUM | 5.3 | 0.3% | Mar 7, 2026 | The MDJM Event Management plugin for WordPress is vulnerable to unauthorized data modification due to a missing capabili... |
| CVE-2026-25073 | MEDIUM | 5.4 | 0.2% | Mar 7, 2026 | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a stored cross-site scripting vulnerabil... |
| CVE-2026-25072 | CRITICAL | 9.8 | 0.5% | Mar 7, 2026 | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a predictable session identifier vulnera... |
| CVE-2026-25071 | HIGH | 7.5 | 0.5% | Mar 7, 2026 | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability i... |
| CVE-2026-25070 | CRITICAL | 9.8 | 3.0% | Mar 7, 2026 | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in... |
| CVE-2026-2371 | MEDIUM | 5.3 | 0.3% | Mar 7, 2026 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Insecure Direct Object Referenc... |
| CVE-2026-1981 | MEDIUM | 4.3 | 0.3% | Mar 7, 2026 | The HUMN-1 AI Website Scanner & Human Certification by Winston AI plugin for WordPress is vulnerable to unauthorized mod... |
| CVE-2026-1644 | MEDIUM | 4.3 | 0.2% | Mar 7, 2026 | The WP Frontend Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2026-3233 | — | — | — | Mar 6, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-30244 | HIGH | 7.5 | 0.4% | Mar 6, 2026 | Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate work... |
| CVE-2026-30242 | HIGH | 8.5 | 0.3% | Mar 6, 2026 | Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/seri... |
| CVE-2026-30241 | HIGH | 8.2 | 0.4% | Mar 6, 2026 | Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDept... |
| CVE-2026-30238 | MEDIUM | 6.1 | 0.3% | Mar 6, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, a... |
| CVE-2026-30237 | MEDIUM | 6.1 | 0.2% | Mar 6, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.155, 25.0.88, a... |
| CVE-2026-27142 | MEDIUM | 6.1 | 0.3% | Mar 6, 2026 | Actions which insert URLs into the content attribute of HTML meta tags are not escaped. This can allow XSS if the meta t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now