2026 CVE Vulnerabilities

48,546 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28169MEDIUM5.3Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
CVE-2026-28146MEDIUM6.5Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 vers...
CVE-2026-28143HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
CVE-2026-28141HIGH7.1Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
CVE-2026-28140HIGH7.5Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
CVE-2026-28139CRITICAL9.8Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
CVE-2026-28111HIGH8.8Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
CVE-2026-28082HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
CVE-2026-28005CRITICAL9.8Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
CVE-2026-25403MEDIUM6.5Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVE-2026-19045MEDIUM5.3A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog...
CVE-2026-19044MEDIUM5.3A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of...
CVE-2026-15246MEDIUM4.3The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, no...
CVE-2026-64993CRITICAL9.1Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remo...
CVE-2026-5134CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Info...
CVE-2026-19041MEDIUM6.3A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageSe...
CVE-2026-19040MEDIUM6.3A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/...
CVE-2026-18501MEDIUM6.4The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre...
CVE-2026-16731HIGH8.3OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authe...
CVE-2026-16316MEDIUM4.3OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame...
CVE-2026-16315HIGH8.7OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authe...
CVE-2026-12605CRITICAL9.6In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfrestt...
CVE-2026-70556MEDIUM5.1Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint h...
CVE-2026-66733HIGH8.7Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enque...
CVE-2026-66732HIGH8.3Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager whe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now