2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15025HIGH7.5The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to ...
CVE-2026-13440HIGH7.2The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for ...
CVE-2026-13110MEDIUM5.3The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and includin...
CVE-2026-65880CRITICAL10Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form proce...
CVE-2026-63303MEDIUM5.1A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fai...
CVE-2026-63302MEDIUM5.1Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated at...
CVE-2026-63301HIGH7In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding...
CVE-2026-18029MEDIUM6.3Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a s...
CVE-2026-18028LOW2.3The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of ...
CVE-2026-17072LOW3.3A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC...
CVE-2026-65624MEDIUM6.9Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote ...
CVE-2026-59248HIGH8.7Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP...
CVE-2026-58246MEDIUM4.3SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagn...
CVE-2026-16462CRITICAL9.8In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker ...
CVE-2026-14785HIGH7.5The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all ver...
CVE-2026-14328HIGH8.8The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privil...
CVE-2026-11841CRITICAL9.4An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileac...
CVE-2026-11598MEDIUM5The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all ...
CVE-2026-10207HIGH7.5The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2....
CVE-2026-9680MEDIUM5.8Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP...
CVE-2026-8167MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solu...
CVE-2026-61376HIGH8.6ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings....
CVE-2026-59764HIGH8.6ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vu...
CVE-2026-44387MEDIUM5.2ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. I...
CVE-2026-15267MEDIUM6.5The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now