2026 CVE Vulnerabilities

48,535 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-47825HIGH8.6Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies in certain configu...
CVE-2026-47261HIGH7.5Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is gi...
CVE-2026-45441HIGH7.5Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions.
CVE-2026-45437HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Product Filter Widget for Elementor <= 1.0.6 versions.
CVE-2026-42775HIGH7.1Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.7.2 versions.
CVE-2026-42687HIGH8.1Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.
CVE-2026-42686HIGH7.1Subscriber Cross Site Scripting (XSS) in EventPrime <= 4.3.2.1 versions.
CVE-2026-42668HIGH7.5Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions.
CVE-2026-42667HIGH7.5Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions.
CVE-2026-42666HIGH7.5Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.
CVE-2026-42664HIGH8.2Unauthenticated Broken Access Control in AI Product Search for WooCommerce &#8211; Motive Commerce Search <= 1.38.2 vers...
CVE-2026-42661HIGH8.8Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.
CVE-2026-42658HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.3.8 versions.
CVE-2026-42650HIGH7.2Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions.
CVE-2026-42649HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Favicon Rotator <= 1.2.11 versions.
CVE-2026-42411HIGH8.1Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions.
CVE-2026-42384HIGH7.5Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.
CVE-2026-40791HIGH7.1Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions.
CVE-2026-40789HIGH7.5Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions.
CVE-2026-40788HIGH7.1Subscriber Broken Access Control in ChatBot <= 7.9.7 versions.
CVE-2026-40787HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions.
CVE-2026-40785HIGH7.1Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions.
CVE-2026-40781HIGH7.5Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions.
CVE-2026-40779HIGH7.7Contributor Arbitrary File Deletion in Link Library <= 7.8.8 versions.
CVE-2026-40776HIGH7.5Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now