2026 CVE Vulnerabilities
50,911 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39651 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Exploiting Incorrectly Configure... |
| CVE-2026-39650 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in Unitech Web UnitechPay unitechpay-paiements-mobile-money allows Exploiting Incorr... |
| CVE-2026-39649 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in themebeez Royale News royale-news allows Exploiting Incorrectly Configured Access... |
| CVE-2026-39648 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in themebeez Cream Blog cream-blog allows Exploiting Incorrectly Configured Access C... |
| CVE-2026-39647 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | Server-Side Request Forgery (SSRF) vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-mus... |
| CVE-2026-39646 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bozdoz Leaflet Map... |
| CVE-2026-39645 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Global Payments GlobalPayments WooCommerce global-payments-woocommer... |
| CVE-2026-39644 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows Exploiting Incorrectly Config... |
| CVE-2026-39643 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in Payment Plugins Payment Plugins for PayPal WooCommerce pymntpl-paypal-woocommerce... |
| CVE-2026-39641 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Skywarrior Blackfyre blackfyre allows Cross Site Request Forgery.This... |
| CVE-2026-39639 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in redpixelstudios RPS Include Content rps-include-content allows Exploiting Incorre... |
| CVE-2026-39638 | MEDIUM | 5.9 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Qubely qub... |
| CVE-2026-39637 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in SpabRice Mogi mogi allows Exploiting Incorrectly Configured Access Control Securi... |
| CVE-2026-39636 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh ... |
| CVE-2026-39635 | MEDIUM | 5.4 | 0.1% | Apr 8, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Magazine grandmagazine allows Cross Site Request For... |
| CVE-2026-39634 | MEDIUM | 5.4 | 0.1% | Apr 8, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Portfolio grandportfolio allows Cross Site Request F... |
| CVE-2026-39633 | MEDIUM | 6.5 | 0.1% | Apr 8, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Car Rental grandcarrental allows Cross Site Request ... |
| CVE-2026-39632 | MEDIUM | 6.5 | 0.1% | Apr 8, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Cross Site Request Forgery.Thi... |
| CVE-2026-39631 | MEDIUM | 4.9 | 0.3% | Apr 8, 2026 | Missing Authorization vulnerability in Ronik@UnlimitedWP WPSchoolPress wpschoolpress allows Exploiting Incorrectly Confi... |
| CVE-2026-39630 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Getty Images Getty Images getty-images allows Server Side Request Fo... |
| CVE-2026-39629 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes Uminex uminex ... |
| CVE-2026-39628 | MEDIUM | 5.3 | 0.3% | Apr 8, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes DukaMarket duk... |
| CVE-2026-39627 | MEDIUM | 4.3 | 0.1% | Apr 8, 2026 | Missing Authorization vulnerability in wproyal Ashe ashe allows Exploiting Incorrectly Configured Access Control Securit... |
| CVE-2026-39626 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes Armania armani... |
| CVE-2026-39625 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in kutethemes TechOne techon... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now