2026 CVE Vulnerabilities

70,357 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28778CRITICAL9.8International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/ins...
CVE-2026-28777CRITICAL9.8International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account....
CVE-2026-28776CRITICAL9.8International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for th...
CVE-2026-28775CRITICAL9.8An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Cor...
CVE-2026-28774HIGH8.8An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting...
CVE-2026-28773HIGH8.8The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series Sup...
CVE-2026-28772MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability in the /IDC_Logging/index.cgi endpoint of International Datacasting...
CVE-2026-28771MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /index.cgi endpoint of International Datacasting Corp...
CVE-2026-2732MEDIUM5.4The Enable Media Replace plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capa...
CVE-2026-2363MEDIUM6.5The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the...
CVE-2026-28770HIGH8.8Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corp...
CVE-2026-28769MEDIUM6.5A path traversal vulnerability exists in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporatio...
CVE-2026-2025HIGH7.5The Mail Mint WordPress plugin before 1.19.5 does not have authorization in one of its REST API endpoint, allowing unau...
CVE-2026-3242MEDIUM4.8In Concrete CMS below version 9.4.8, a rogue administrator can add stored XSS via the Switch Language block.  The Concre...
CVE-2026-3241MEDIUM4.8In Concrete CMS below version 9.4.8, a stored cross-site scripting (XSS) vulnerability exists in the "Legacy Form" block...
CVE-2026-3240MEDIUM4.8In Concrete CMS below version 9.4.8, a user with permission to edit a page with element Legacy form can perform a stored...
CVE-2026-2994MEDIUM6.8Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configu...
CVE-2026-3452HIGH7.2Concrete CMS below version 9.4.8 is vulnerable to Remote Code Execution by stored PHP object injection into the Express ...
CVE-2026-3244MEDIUM4.8In Concrete CMS below version 9.4.8, A stored cross-site scripting (XSS) vulnerability exists in the search block where ...
CVE-2026-2292MEDIUM4.4The Morkva UA Shipping plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi...
CVE-2026-2289MEDIUM4.4The Taskbuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2026-1980MEDIUM5.3The WPBookit plugin for WordPress is vulnerable to unauthorized data disclosure due to a missing authorization check on ...
CVE-2026-1945HIGH7.2The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_ema...
CVE-2026-1651MEDIUM6.5The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' para...
CVE-2026-1273HIGH7.2The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server-S...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now