2026 CVE Vulnerabilities

70,192 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27989HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27988HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27987HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27986HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27985HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27984CRITICAL9Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options ...
CVE-2026-27983CRITICAL9.8Incorrect Privilege Assignment vulnerability in designthemes LMS Elementor Pro lms-elementor-pro allows Privilege Escala...
CVE-2026-27982MEDIUM6.1An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled...
CVE-2026-27541HIGH7.2Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privil...
CVE-2026-27439CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Dentario dentario allows Object Injection.This issue affects...
CVE-2026-27438CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Kingler kingler allows Object Injection.This issue affects K...
CVE-2026-27437CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Tennis Club tennis-sportclub allows Object Injection.This is...
CVE-2026-27428HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eagle-Themes Eagle...
CVE-2026-27417CRITICAL9.8Deserialization of Untrusted Data vulnerability in SeventhQueen Sweet Date sweetdate allows Object Injection.This issue ...
CVE-2026-27411MEDIUM5.4Guessable CAPTCHA vulnerability in jp-secure SiteGuard WP Plugin siteguard allows Functionality Bypass.This issue affect...
CVE-2026-27406HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Joe Dolson My Tickets my-tickets allows Retrieve Embe...
CVE-2026-27396HIGH7.3Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Ac...
CVE-2026-27390HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Add...
CVE-2026-27389CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Add...
CVE-2026-27388HIGH7.5Missing Authorization vulnerability in designthemes DesignThemes Booking Manager designthemes-booking-manager allows Exp...
CVE-2026-27386HIGH7.5Missing Authorization vulnerability in designthemes DesignThemes Directory Addon designthemes-directory-addon allows Exp...
CVE-2026-27385HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Desig...
CVE-2026-27384CRITICAL9Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Access...
CVE-2026-27383HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27382HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RadiusTheme Metro ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now