2026 CVE Vulnerabilities
53,206 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1461 | MEDIUM | 6.5 | 0.2% | Feb 19, 2026 | The Simple Membership plugin for WordPress is vulnerable to Improper Handling of Missing Values in all versions up to, a... |
| CVE-2026-1219 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure Dir... |
| CVE-2026-2736 | MEDIUM | 6.1 | 0.1% | Feb 19, 2026 | Reflected Cross-site Scripting (XSS) in Alkacon's OpenCms v18.0, which allows an attacker to execute JavaScript code in ... |
| CVE-2026-2735 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | Stored Cross-Site Scripting (XSS) in Alkacon's OpenCms v18.0, which occurs when user input is not properly validated whe... |
| CVE-2026-27094 | MEDIUM | 6.5 | 0.1% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoDaddy CoBlocks c... |
| CVE-2026-27092 | MEDIUM | 6.5 | 0.3% | Feb 19, 2026 | Missing Authorization vulnerability in Greg Winiarski WPAdverts wpadverts allows Exploiting Incorrectly Configured Acces... |
| CVE-2026-27090 | MEDIUM | 4.3 | 0.1% | Feb 19, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Moose Kenta Companion kenta-companion allows Cross Site Request Fo... |
| CVE-2026-27074 | MEDIUM | 6.5 | 0.1% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vaakash Shortcoder... |
| CVE-2026-27069 | MEDIUM | 6.5 | 0.1% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soleda... |
| CVE-2026-27059 | MEDIUM | 6.5 | 0.1% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ... |
| CVE-2026-27058 | MEDIUM | 6.5 | 0.1% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ... |
| CVE-2026-27057 | MEDIUM | 6.5 | 0.1% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci ... |
| CVE-2026-27056 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in StellarWP iThemes Sync ithemes-sync allows Exploiting Incorrectly Configured Acce... |
| CVE-2026-27055 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in PenciDesign Penci AI SmartContent Creator penci-ai allows Exploiting Incorrectly ... |
| CVE-2026-27050 | MEDIUM | 5.4 | 0.1% | Feb 19, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThimPress RealPress realpress allows Cross Site Request Forgery.This ... |
| CVE-2026-27042 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in WPDeveloper NotificationX notificationx allows Exploiting Incorrectly Configured ... |
| CVE-2026-26361 | MEDIUM | 6.5 | 0.2% | Feb 19, 2026 | Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low p... |
| CVE-2026-25473 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in AA-Team WZone woozone allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2026-25472 | MEDIUM | 6.5 | 0.1% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion... |
| CVE-2026-25463 | MEDIUM | 6.5 | 0.1% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpEstate Wpresiden... |
| CVE-2026-25459 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in uixthemes Sober sober allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2026-25453 | MEDIUM | 6.5 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdempfle Advanced ... |
| CVE-2026-25451 | MEDIUM | 6.5 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Pa... |
| CVE-2026-25441 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | Missing Authorization vulnerability in varunvairavanlc LeadConnector leadconnector allows Exploiting Incorrectly Configu... |
| CVE-2026-25432 | MEDIUM | 6.5 | 0.2% | Feb 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omni... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now