2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5208 | HIGH | 7.2 | 1.0% | Apr 8, 2026 | Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary c... |
| CVE-2026-3396 | HIGH | 7.5 | 1.5% | Apr 8, 2026 | WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter... |
| CVE-2026-3243 | HIGH | 8.8 | 0.8% | Apr 8, 2026 | The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path... |
| CVE-2026-39684 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39681 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39679 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39677 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39671 | HIGH | 7.1 | 0.1% | Apr 8, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dotstore Extra Fees Plugin for WooCommerce woo-conditional-product-fe... |
| CVE-2026-39623 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39621 | HIGH | 8.8 | 0.1% | Apr 8, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web ... |
| CVE-2026-39613 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39611 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39544 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39538 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39497 | HIGH | 7.6 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 FOX woo... |
| CVE-2026-39496 | HIGH | 7.6 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayMai... |
| CVE-2026-39495 | HIGH | 8.5 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NSquared Simply Sc... |
| CVE-2026-39487 | HIGH | 7.6 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amel... |
| CVE-2026-39486 | HIGH | 8.5 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill Download ... |
| CVE-2026-39479 | HIGH | 7.6 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force O... |
| CVE-2026-39475 | HIGH | 7.6 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User F... |
| CVE-2026-39466 | HIGH | 7.6 | 0.3% | Apr 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMU DEV - Your Al... |
| CVE-2026-4483 | HIGH | 7 | 0.3% | Apr 8, 2026 | An exposed IOCTL with an insufficient access control vulnerability has been identified in the utility, MxGeneralIo, for... |
| CVE-2026-4808 | HIGH | 7.2 | 0.6% | Apr 8, 2026 | The Gerador de Certificados – DevApps plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t... |
| CVE-2026-4338 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | The ActivityPub WordPress plugin before 8.0.2 does not properly filter posts to be displayed, allowed unauthenticated us... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now