2026 CVE Vulnerabilities
51,063 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2726 | MEDIUM | 4.3 | 0.2% | Mar 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.8.7, 18.9 before 18.9.3, and ... |
| CVE-2026-27659 | MEDIUM | 4.6 | 0.1% | Mar 25, 2026 | Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to properly validate ... |
| CVE-2026-27656 | MEDIUM | 6.1 | 0.2% | Mar 25, 2026 | Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate ... |
| CVE-2026-27046 | MEDIUM | 6.5 | 0.4% | Mar 25, 2026 | Missing Authorization vulnerability in Kaira StoreCustomizer woocustomizer allows Exploiting Incorrectly Configured Acce... |
| CVE-2026-26233 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to rate limit login r... |
| CVE-2026-25645 | MEDIUM | 5.5 | 0.2% | Mar 25, 2026 | Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a... |
| CVE-2026-25469 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in ViaBill for WooCommerce ViaBill – WooCommerce viabill-woocommerce allows Exploiti... |
| CVE-2026-25465 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople CP Mult... |
| CVE-2026-25462 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in avalex avalex avalex allows Exploiting Incorrectly Configured Access Control Secu... |
| CVE-2026-25460 | MEDIUM | 6.3 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in LiquidThemes Ave Core ave-core allows Exploiting Incorrectly Configured Access Co... |
| CVE-2026-25455 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Exp... |
| CVE-2026-25454 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in MVPThemes The League the-league allows Exploiting Incorrectly Configured Access C... |
| CVE-2026-25437 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in سید محمدامین هاشمی GZSEO gzseo allows Exploiting Incorrectly Configured Access Co... |
| CVE-2026-25430 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in CRM Perks Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja... |
| CVE-2026-25417 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileG... |
| CVE-2026-25398 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in Webilia Inc. Vertex Addons for Elementor addons-for-elementor-builder allows Expl... |
| CVE-2026-25390 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in Saad Iqbal New User Approve new-user-approve allows Exploiting Incorrectly Config... |
| CVE-2026-25365 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in Özgür KARALAR Kargo Takip kargo-takip-turkiye allows Exploiting Incorrectly Confi... |
| CVE-2026-25355 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Sanzo san... |
| CVE-2026-25344 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme Review Schema re... |
| CVE-2026-25339 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allo... |
| CVE-2026-25328 | MEDIUM | 6.8 | 0.4% | Mar 25, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Product File... |
| CVE-2026-25327 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Explo... |
| CVE-2026-25034 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorr... |
| CVE-2026-25009 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in raratheme Education Zone education-zone allows Exploiting Incorrectly Configured ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now