2026 CVE Vulnerabilities

48,516 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-40739HIGH8.1Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
CVE-2026-40736HIGH8.1Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
CVE-2026-40735HIGH8.1Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
CVE-2026-40731HIGH8.1Unauthenticated Local File Inclusion in ChapterOne <= 1.7 versions.
CVE-2026-40726HIGH8.2Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions.
CVE-2026-40721HIGH7.5Contributor Local File Inclusion in Element Pack Pro <= 9.0.6 versions.
CVE-2026-39598HIGH8Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell t...
CVE-2026-39597HIGH7.1Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions.
CVE-2026-39582HIGH8.1Unauthenticated Local File Inclusion in Hitek < 1.8.3 versions.
CVE-2026-39580HIGH8.1Unauthenticated PHP Object Injection in Micdrop <= 1.3.1 versions.
CVE-2026-39573HIGH8.1Unauthenticated PHP Object Injection in Mildhill <= 1.5 versions.
CVE-2026-39568HIGH8.1Unauthenticated Local File Inclusion in Mr. SEO <= 2.0 versions.
CVE-2026-39567HIGH8.1Unauthenticated PHP Object Injection in Santé <= 1.5.1 versions.
CVE-2026-39558HIGH8.1Unauthenticated Local File Inclusion in Malmö <= 2.2 versions.
CVE-2026-39557HIGH8.1Unauthenticated PHP Object Injection in NeoBeat <= 1.7 versions.
CVE-2026-39554HIGH8.1Unauthenticated PHP Object Injection in Fidalgo <= 1.2.2 versions.
CVE-2026-39549HIGH8.1Unauthenticated Local File Inclusion in Aperitif <= 1.5 versions.
CVE-2026-39548HIGH7.1Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions.
CVE-2026-39547HIGH8.1Unauthenticated Local File Inclusion in Getaway < 1.8 versions.
CVE-2026-39546HIGH7.6Subscriber Privilege Escalation in MultiLoca <= 4.2.15 versions.
CVE-2026-39545HIGH8.1Unauthenticated PHP Object Injection in Zermatt <= 1.6.1 versions.
CVE-2026-39539HIGH8.1Unauthenticated PHP Object Injection in Alloggio - Hotel Booking <= 2.1.2 versions.
CVE-2026-39537HIGH8.1Unauthenticated Local File Inclusion in Mikado Core <= 1.6 versions.
CVE-2026-39522HIGH8.1Unauthenticated Local File Inclusion in Solene <= 3.4 versions.
CVE-2026-39446HIGH8.1Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now