2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-61961HIGH7.1Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
CVE-2026-61959MEDIUM6.5Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.
CVE-2026-54489CRITICAL9.8Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Informati...
CVE-2026-53976CRITICAL9.3OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and...
CVE-2026-53975CRITICAL9.8OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execu...
CVE-2026-34502HIGH7.5Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache ...
CVE-2026-34501HIGH7.5Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Por...
CVE-2026-34191CRITICAL9.1Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Ru...
CVE-2026-32548MEDIUM5.3Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
CVE-2026-32469MEDIUM5.3Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
CVE-2026-32327CRITICAL9.1A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses ...
CVE-2026-28183Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-28180MEDIUM5.3Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
CVE-2026-28179MEDIUM5.9Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
CVE-2026-28178MEDIUM6.5Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
CVE-2026-28177HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
CVE-2026-28172HIGH7.1Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
CVE-2026-28169MEDIUM5.3Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
CVE-2026-28146MEDIUM6.5Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 vers...
CVE-2026-28143HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
CVE-2026-28141HIGH7.1Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
CVE-2026-28140HIGH7.5Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
CVE-2026-28139CRITICAL9.8Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
CVE-2026-28111HIGH8.8Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
CVE-2026-28082HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now