2026 CVE Vulnerabilities

51,359 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-4060HIGH7.5The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions u...
CVE-2026-7611HIGH8.1A vulnerability was found in TRENDnet TEW-821DAP up to 1.12B01. This impacts the function platform_do_upgrade_cameo_dev ...
CVE-2026-7610HIGH8.1A vulnerability has been found in TRENDnet TEW-821DAP 1.12B01. This affects an unknown function of the file /www/cgi/ssi...
CVE-2026-7609HIGH8.8A flaw has been found in TRENDnet TEW-821DAP up to 1.12B01. The impacted element is the function tools_diagnostic of the...
CVE-2026-7491HIGH8.6School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote att...
CVE-2026-7490HIGH7.2CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to up...
CVE-2026-7489HIGH8.8CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary ...
CVE-2026-7608HIGH8A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic...
CVE-2026-5324HIGH7.2The Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versio...
CVE-2026-7649HIGH7.5The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is...
CVE-2026-7607HIGH8.8A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function auto_update_firmware...
CVE-2026-7606HIGH8.1A weakness has been identified in TRENDnet TEW-821DAP 1.12B01. This issue affects the function find_hwid/new_gui_update_...
CVE-2026-6229HIGH7.2The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and incl...
CVE-2026-2052HIGH8.8The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vuln...
CVE-2026-7647HIGH8.1The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3...
CVE-2026-7049HIGH7.2The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery...
CVE-2026-5113HIGH7.2The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in v...
CVE-2026-5112HIGH7.2The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to an...
CVE-2026-5111HIGH7.2The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10...
CVE-2026-5110HIGH7.2The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to an...
CVE-2026-5109HIGH7.2The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10...
CVE-2026-7641HIGH8.8The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up ...
CVE-2026-6963HIGH8.8The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the w...
CVE-2026-43824HIGH7.7In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
CVE-2026-7598HIGH7.3A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_passwo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now