2026 CVE Vulnerabilities
70,017 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2893 | MEDIUM | 6.5 | 0.2% | Mar 5, 2026 | The Page and Post Clone plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' parameter in the content_... |
| CVE-2026-28552 | HIGH | 7.5 | 0.3% | Mar 5, 2026 | Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect av... |
| CVE-2026-28550 | MEDIUM | 4.7 | 0.1% | Mar 5, 2026 | Race condition vulnerability in the security control module. Impact: Successful exploitation of this vulnerability may a... |
| CVE-2026-28545 | MEDIUM | 4.7 | 0.1% | Mar 5, 2026 | Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect av... |
| CVE-2026-28544 | MEDIUM | 4.7 | 0.1% | Mar 5, 2026 | Race condition vulnerability in the printing module. Impact: Successful exploitation of this vulnerability may affect av... |
| CVE-2026-28543 | MEDIUM | 4.7 | 0.1% | Mar 5, 2026 | Race condition vulnerability in the maintenance and diagnostics module. Impact: Successful exploitation of this vulnerab... |
| CVE-2026-28541 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Permission control vulnerability in the cellular_data module. Impact: Successful exploitation of this vulnerability may ... |
| CVE-2026-28540 | LOW | 3.3 | 0.1% | Mar 5, 2026 | Out-of-bounds character read vulnerability in Bluetooth. Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2026-28539 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerabilit... |
| CVE-2026-28538 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability... |
| CVE-2026-28537 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | Double free vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect availab... |
| CVE-2026-21786 | LOW | 3.3 | 0.1% | Mar 5, 2026 | HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application... |
| CVE-2026-1321 | HIGH | 8.1 | 0.4% | Mar 5, 2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up t... |
| CVE-2026-2743 | CRITICAL | 9.8 | 0.8% | Mar 5, 2026 | Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected fea... |
| CVE-2026-28536 | HIGH | 8.1 | 0.2% | Mar 5, 2026 | Authentication bypass vulnerability in the device authentication module. Impact: Successful exploitation of this vulnera... |
| CVE-2026-25702 | CRITICAL | 9.8 | 0.2% | Mar 5, 2026 | A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causi... |
| CVE-2026-1678 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | dns_unpack_name() caches the buffer tailroom once and reuses it while appending DNS labels. As the buffer grows, the cac... |
| CVE-2026-3072 | MEDIUM | 4.3 | 0.2% | Mar 5, 2026 | The Media Library Assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap... |
| CVE-2026-30777 | MEDIUM | 6.5 | 0.3% | Mar 5, 2026 | EC-CUBE provided by EC-CUBE CO.,LTD. contains a multi-factor authentication (MFA) bypass vulnerability. An attacker who ... |
| CVE-2026-2418 | CRITICAL | 9.1 | 0.2% | Mar 5, 2026 | The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Sales... |
| CVE-2026-29128 | CRITICAL | 10 | 0.3% | Mar 5, 2026 | IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zeb... |
| CVE-2026-29053 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | Ghost is a Node.js content management system. From version 0.7.2 to 6.19.0, specifically crafted malicious themes can ex... |
| CVE-2026-29052 | MEDIUM | 6.1 | 0.2% | Mar 5, 2026 | The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and ef... |
| CVE-2026-28137 | HIGH | 7.1 | 0.1% | Mar 5, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs MediC... |
| CVE-2026-28135 | HIGH | 8.2 | 0.2% | Mar 5, 2026 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in WP Royal Royal Elementor Addons royal-elemento... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now