2026 CVE Vulnerabilities

70,268 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27990HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27989HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27988HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27987HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27986HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27985HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-27984CRITICAL9Improper Control of Generation of Code ('Code Injection') vulnerability in Marketing Fire Widget Options widget-options ...
CVE-2026-27983CRITICAL9.8Incorrect Privilege Assignment vulnerability in designthemes LMS Elementor Pro lms-elementor-pro allows Privilege Escala...
CVE-2026-27982MEDIUM6.1An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled...
CVE-2026-27541HIGH7.2Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privil...
CVE-2026-27439CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Dentario dentario allows Object Injection.This issue affects...
CVE-2026-27438CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Kingler kingler allows Object Injection.This issue affects K...
CVE-2026-27437CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThemeREX Tennis Club tennis-sportclub allows Object Injection.This is...
CVE-2026-27428HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eagle-Themes Eagle...
CVE-2026-27417CRITICAL9.8Deserialization of Untrusted Data vulnerability in SeventhQueen Sweet Date sweetdate allows Object Injection.This issue ...
CVE-2026-27411MEDIUM5.4Guessable CAPTCHA vulnerability in jp-secure SiteGuard WP Plugin siteguard allows Functionality Bypass.This issue affect...
CVE-2026-27406HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in Joe Dolson My Tickets my-tickets allows Retrieve Embe...
CVE-2026-27396HIGH7.3Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Ac...
CVE-2026-27390HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Add...
CVE-2026-27389CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Add...
CVE-2026-27388HIGH7.5Missing Authorization vulnerability in designthemes DesignThemes Booking Manager designthemes-booking-manager allows Exp...
CVE-2026-27386HIGH7.5Missing Authorization vulnerability in designthemes DesignThemes Directory Addon designthemes-directory-addon allows Exp...
CVE-2026-27385HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Desig...
CVE-2026-27384CRITICAL9Improper Validation of Specified Quantity in Input vulnerability in BoldGrid W3 Total Cache w3-total-cache allows Access...
CVE-2026-27383HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now