2026 CVE Vulnerabilities
51,054 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32541 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in Premmerce Premmerce Redirect Manager premmerce-redirect-manager allows Exploiting... |
| CVE-2026-32535 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiti... |
| CVE-2026-32533 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in LatePoint LatePoint latepoint allows Exploiting Incorr... |
| CVE-2026-32527 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in CRM Perks WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Nin... |
| CVE-2026-32521 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Northern Beaches W... |
| CVE-2026-32514 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in Anton Voytenko Petitioner petitioner allows Exploiting Incorrectly Configured Acc... |
| CVE-2026-32511 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Mikado-Themes Stål stal allows Object Injection.This issue affects St... |
| CVE-2026-32510 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Edge-Themes Kamperen kamperen allows Object Injection.This issue affe... |
| CVE-2026-32509 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Edge-Themes Gracey gracey allows Object Injection.This issue affects ... |
| CVE-2026-32508 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Mikado-Themes Halstein halstein allows Object Injection.This issue af... |
| CVE-2026-32507 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Elated-Themes Leroux leroux allows Object Injection.This issue affect... |
| CVE-2026-32506 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Deserialization of Untrusted Data vulnerability in Edge-Themes Archicon archicon allows Object Injection.This issue affe... |
| CVE-2026-32497 | MEDIUM | 5.3 | 0.2% | Mar 25, 2026 | Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This is... |
| CVE-2026-32496 | MEDIUM | 6.8 | 0.4% | Mar 25, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NYSL Spam Protect for Co... |
| CVE-2026-32492 | MEDIUM | 5.3 | 0.3% | Mar 25, 2026 | Authentication Bypass by Spoofing vulnerability in Joe Dolson My Tickets my-tickets allows Identity Spoofing.This issue ... |
| CVE-2026-32491 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP Revie... |
| CVE-2026-32490 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP TripA... |
| CVE-2026-32489 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in bPlugins B Blocks b-blocks allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2026-32483 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly... |
| CVE-2026-31914 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hookandhook WP Cou... |
| CVE-2026-2995 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.1... |
| CVE-2026-2973 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 1... |
| CVE-2026-2726 | MEDIUM | 4.3 | 0.2% | Mar 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and ... |
| CVE-2026-27659 | MEDIUM | 4.6 | 0.1% | Mar 25, 2026 | Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to properly validate ... |
| CVE-2026-27656 | MEDIUM | 6.1 | 0.2% | Mar 25, 2026 | Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now