2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-58246MEDIUM4.3SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagn...
CVE-2026-16462CRITICAL9.8In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker ...
CVE-2026-14785HIGH7.5The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all ver...
CVE-2026-14328HIGH8.8The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privil...
CVE-2026-11841CRITICAL9.4An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileac...
CVE-2026-11598MEDIUM5The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all ...
CVE-2026-10207HIGH7.5The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2....
CVE-2026-9680MEDIUM5.8Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP...
CVE-2026-8167MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solu...
CVE-2026-61376HIGH8.6ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings....
CVE-2026-59764HIGH8.6ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vu...
CVE-2026-44387MEDIUM5.2ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. I...
CVE-2026-15267MEDIUM6.5The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL ...
CVE-2026-14516HIGH7.5The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injec...
CVE-2026-14171MEDIUM6.1An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick ...
CVE-2026-14170Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-14169HIGH8.1Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted in...
CVE-2026-14168HIGH8.8A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of th...
CVE-2026-14167HIGH8.8A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level inclu...
CVE-2026-13161HIGH7.5The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection vi...
CVE-2026-12800HIGH7.5The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code'...
CVE-2026-55977LOW3.3Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the applicatio...
CVE-2026-15730MEDIUM6.4The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ...
CVE-2026-15673MEDIUM4.4The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-15671MEDIUM4.9The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now