2026 CVE Vulnerabilities
53,108 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28104 | MEDIUM | 6.5 | 0.2% | Mar 5, 2026 | Missing Authorization vulnerability in Aryan Shirani Bid Abadi Site Suggest site-suggest allows Accessing Functionality ... |
| CVE-2026-28078 | MEDIUM | 4.9 | 0.4% | Mar 5, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Stylemix uListing ulisti... |
| CVE-2026-28071 | MEDIUM | 6.3 | 0.2% | Mar 5, 2026 | Missing Authorization vulnerability in PixFort pixfort Core pixfort-core allows Exploiting Incorrectly Configured Access... |
| CVE-2026-28038 | MEDIUM | 6.5 | 0.3% | Mar 5, 2026 | Missing Authorization vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons all... |
| CVE-2026-28036 | MEDIUM | 6.4 | 0.2% | Mar 5, 2026 | Server-Side Request Forgery (SSRF) vulnerability in SkatDesign Ratatouille ratatouille allows Server Side Request Forger... |
| CVE-2026-27982 | MEDIUM | 6.1 | 0.2% | Mar 5, 2026 | An open redirect vulnerability exists in django-allauth versions prior to 65.14.1 when SAML IdP initiated SSO is enabled... |
| CVE-2026-27411 | MEDIUM | 5.4 | 0.2% | Mar 5, 2026 | Guessable CAPTCHA vulnerability in jp-secure SiteGuard WP Plugin siteguard allows Functionality Bypass.This issue affect... |
| CVE-2026-27362 | MEDIUM | 6.5 | 0.2% | Mar 5, 2026 | Missing Authorization vulnerability in kamleshyadav WP Bakery Autoresponder Addon vc-autoresponder-addon allows Exploiti... |
| CVE-2026-27354 | MEDIUM | 6.5 | 0.2% | Mar 5, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Woo... |
| CVE-2026-27344 | MEDIUM | 5.9 | 0.2% | Mar 5, 2026 | Missing Authorization vulnerability in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Acce... |
| CVE-2026-23799 | MEDIUM | 6.5 | 0.3% | Mar 5, 2026 | Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2026-23546 | MEDIUM | 6.5 | 0.4% | Mar 5, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in RadiusTheme Classified Listing classified-listing all... |
| CVE-2026-22459 | MEDIUM | 6.5 | 0.3% | Mar 5, 2026 | Missing Authorization vulnerability in Blend Media WordPress CTA easy-sticky-sidebar allows Exploiting Incorrectly Confi... |
| CVE-2026-3523 | MEDIUM | 4.9 | 0.5% | Mar 5, 2026 | The Apocalypse Meow plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, ... |
| CVE-2026-3034 | MEDIUM | 6.4 | 0.2% | Mar 5, 2026 | The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _ob_spacera... |
| CVE-2026-2899 | MEDIUM | 6.5 | 0.2% | Mar 5, 2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and ... |
| CVE-2026-29125 | MEDIUM | 4.7 | 0.1% | Mar 5, 2026 | IDC SFX2100 Satalite Recievers set the `/etc/resolv.conf` file to be world-writable by any local user, allowing DNS reso... |
| CVE-2026-29122 | MEDIUM | 5.5 | 0.1% | Mar 5, 2026 | International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid... |
| CVE-2026-22052 | MEDIUM | 4.3 | 0.2% | Mar 5, 2026 | ONTAP versions 9.12.1 and higher with S3 NAS buckets are susceptible to an information disclosure vulnerability. Success... |
| CVE-2026-2297 | MEDIUM | 5.7 | 0.2% | Mar 4, 2026 | The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (... |
| CVE-2026-29086 | MEDIUM | 5.4 | 0.2% | Mar 4, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCo... |
| CVE-2026-29085 | MEDIUM | 6.5 | 0.2% | Mar 4, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when usin... |
| CVE-2026-27898 | MEDIUM | 5.4 | 0.2% | Mar 4, 2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to versi... |
| CVE-2026-27801 | MEDIUM | 5.9 | 0.3% | Mar 4, 2026 | Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden ve... |
| CVE-2026-22040 | MEDIUM | 5.3 | 0.2% | Mar 4, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In version 0.24.6, by generating a combined traffi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now