2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-65541HIGH7.3Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
CVE-2026-65523HIGH7.5Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0...
CVE-2026-65517HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
CVE-2026-65515HIGH7.1Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
CVE-2026-65513HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
CVE-2026-65509HIGH7.1Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
CVE-2026-65504HIGH7.5Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
CVE-2026-61982HIGH7.1Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
CVE-2026-61964HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
CVE-2026-61963HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
CVE-2026-61961HIGH7.1Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
CVE-2026-34502HIGH7.5Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache ...
CVE-2026-34501HIGH7.5Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Por...
CVE-2026-28177HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
CVE-2026-28172HIGH7.1Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
CVE-2026-28143HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
CVE-2026-28141HIGH7.1Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
CVE-2026-28140HIGH7.5Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
CVE-2026-28111HIGH8.8Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
CVE-2026-28082HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
CVE-2026-16731HIGH8.3OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authe...
CVE-2026-16315HIGH8.7OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authe...
CVE-2026-66733HIGH8.7Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enque...
CVE-2026-66732HIGH8.3Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager whe...
CVE-2026-65551HIGH7.5Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Securit...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now