2026 CVE Vulnerabilities
70,045 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27992 | HIGH | 8.1 | 0.4% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27991 | HIGH | 8.1 | 0.4% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27990 | HIGH | 8.1 | 0.4% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27989 | HIGH | 8.1 | 0.4% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27988 | HIGH | 8.1 | 0.4% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27987 | HIGH | 8.1 | 0.4% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27986 | HIGH | 8.1 | 0.4% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27985 | HIGH | 8.1 | 0.4% | Mar 5, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-27984 | CRITICAL | 9 | 0.3% | Mar 5, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options ... |
| CVE-2026-27983 | CRITICAL | 9.8 | 0.3% | Mar 5, 2026 | Incorrect Privilege Assignment vulnerability in designthemes LMS Elementor Pro lms-elementor-pro allows Privilege Escala... |
| CVE-2026-27982 | MEDIUM | 6.1 | 0.2% | Mar 5, 2026 | An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled... |
| CVE-2026-27541 | HIGH | 7.2 | 0.2% | Mar 5, 2026 | Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privil... |
| CVE-2026-27439 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Dentario dentario allows Object Injection.This issue affects... |
| CVE-2026-27438 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Kingler kingler allows Object Injection.This issue affects K... |
| CVE-2026-27437 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Tennis Club tennis-sportclub allows Object Injection.This is... |
| CVE-2026-27428 | HIGH | 8.5 | 0.3% | Mar 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eagle-Themes Eagle... |
| CVE-2026-27417 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | Deserialization of Untrusted Data vulnerability in SeventhQueen Sweet Date sweetdate allows Object Injection.This issue ... |
| CVE-2026-27411 | MEDIUM | 5.4 | 0.2% | Mar 5, 2026 | Guessable CAPTCHA vulnerability in jp-secure SiteGuard WP Plugin siteguard allows Functionality Bypass.This issue affect... |
| CVE-2026-27406 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Joe Dolson My Tickets my-tickets allows Retrieve Embe... |
| CVE-2026-27396 | HIGH | 7.3 | 0.2% | Mar 5, 2026 | Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Ac... |
| CVE-2026-27390 | HIGH | 8.8 | 0.5% | Mar 5, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Add... |
| CVE-2026-27389 | CRITICAL | 9.8 | 0.4% | Mar 5, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Add... |
| CVE-2026-27388 | HIGH | 7.5 | 0.4% | Mar 5, 2026 | Missing Authorization vulnerability in designthemes DesignThemes Booking Manager designthemes-booking-manager allows Exp... |
| CVE-2026-27386 | HIGH | 7.5 | 0.2% | Mar 5, 2026 | Missing Authorization vulnerability in designthemes DesignThemes Directory Addon designthemes-directory-addon allows Exp... |
| CVE-2026-27385 | HIGH | 7.1 | 0.2% | Mar 5, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Desig... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now