2026 CVE Vulnerabilities
51,070 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24987 | MEDIUM | 6.5 | 0.4% | Mar 25, 2026 | Missing Authorization vulnerability in activity-log.com WP System Log winterlock allows Exploiting Incorrectly Configure... |
| CVE-2026-24972 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in Elated-Themes Elated Listing eltd-listing allows Exploiting Incorrectly Configure... |
| CVE-2026-24964 | MEDIUM | 6.4 | 0.2% | Mar 25, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-... |
| CVE-2026-24376 | MEDIUM | 6.5 | 0.4% | Mar 25, 2026 | Missing Authorization vulnerability in Javier Casares WPVulnerability wpvulnerability allows Exploiting Incorrectly Conf... |
| CVE-2026-24370 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme-one The Grid... |
| CVE-2026-24364 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in weDevs WP User Frontend wp-user-frontend allows Exploiting Incorrectly Configured... |
| CVE-2026-24362 | MEDIUM | 6.4 | 0.2% | Mar 25, 2026 | Missing Authorization vulnerability in bdthemes Ultimate Post Kit ultimate-post-kit allows Exploiting Incorrectly Config... |
| CVE-2026-23972 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocomme... |
| CVE-2026-23635 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, a misconfiguration of ... |
| CVE-2026-22485 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in Ruhul Amin My Album Gallery my-album-gallery allows Exploiting Incorrectly Config... |
| CVE-2026-1712 | MEDIUM | 5.8 | 0.3% | Mar 25, 2026 | Incorrect privilege assignment vulnerability in HYPR Server allows Privilege Escalation.This issue affects HYPR Server: ... |
| CVE-2026-3218 | MEDIUM | 4.8 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Responsive ... |
| CVE-2026-3217 | MEDIUM | 6.1 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal SAML SSO - ... |
| CVE-2026-3216 | MEDIUM | 5 | 0.3% | Mar 25, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal Canvas allows Server Side Request Forgery.This issue a... |
| CVE-2026-3215 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Islandora a... |
| CVE-2026-3214 | MEDIUM | 6.5 | 0.3% | Mar 25, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA allows Functionality Bypass.Thi... |
| CVE-2026-3213 | MEDIUM | 4.7 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam b... |
| CVE-2026-3212 | MEDIUM | 5.4 | 0.1% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Tagify allo... |
| CVE-2026-3211 | MEDIUM | 4.3 | 0.1% | Mar 25, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Theme Negotiation by Rules allows Cross Site Request Forgery.T... |
| CVE-2026-3210 | MEDIUM | 5.3 | 0.2% | Mar 25, 2026 | Incorrect Authorization vulnerability in Drupal Material Icons allows Forceful Browsing.This issue affects Material Icon... |
| CVE-2026-2349 | MEDIUM | 6.1 | 0.1% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal UI Icons al... |
| CVE-2026-2348 | MEDIUM | 5.4 | 0.1% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Quick Edit ... |
| CVE-2026-24750 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | Kiteworks is a private data network (PDN). In Kiteworks Secure Data Forms prior to version 9.2.1, an authenticated attac... |
| CVE-2026-20115 | MEDIUM | 6.1 | 0.2% | Mar 25, 2026 | A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confide... |
| CVE-2026-20114 | MEDIUM | 5.4 | 0.3% | Mar 25, 2026 | A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now