2026 CVE Vulnerabilities

48,521 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-16265MEDIUM6.5The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not r...
CVE-2026-16263HIGH8.8The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not p...
CVE-2026-16262HIGH7.5The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating...
CVE-2026-16258CRITICAL9.8The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing u...
CVE-2026-16041HIGH7.5The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST p...
CVE-2026-16039MEDIUM6.5The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, ...
CVE-2026-16038CRITICAL9.1The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an or...
CVE-2026-16030HIGH8.1The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used t...
CVE-2026-15386MEDIUM5.4The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an att...
CVE-2026-15361HIGH8.1The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does n...
CVE-2026-15359MEDIUM6.5The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allow...
CVE-2026-15245MEDIUM5.4The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript con...
CVE-2026-15215HIGH8.8The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing ...
CVE-2026-15214MEDIUM4.3The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription...
CVE-2026-15032MEDIUM6.1The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an...
CVE-2026-14943HIGH7.5The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 d...
CVE-2026-14331MEDIUM6.1The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a...
CVE-2026-14205CRITICAL9.8The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid...
CVE-2026-49005LOW2.4The root password hash of the device can be obtained through unencrypted information in the firmware.
CVE-2026-19195HIGH7.8A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in th...
CVE-2026-19193HIGH7.8A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys...
CVE-2026-19192HIGH7.8A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C...
CVE-2026-19191HIGH7.8A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code o...
CVE-2026-14365CRITICAL9.8The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in ...
CVE-2026-14364CRITICAL9.8The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via imp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now