2026 CVE Vulnerabilities

55,518 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-24727CRITICAL9.3An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporat...
CVE-2026-15821MEDIUM6.4The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-15739MEDIUM6.4The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' ...
CVE-2026-15704CRITICAL9.8In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authori...
CVE-2026-15346MEDIUM6.1The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '...
CVE-2026-12702MEDIUM4.9In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to...
CVE-2026-16910MEDIUM5.5A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers acc...
CVE-2026-16519HIGH7.3A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads on...
CVE-2026-15755MEDIUM6.4The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Short...
CVE-2026-15665MEDIUM6.4The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-15653MEDIUM6.4The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-15648MEDIUM6.4The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attri...
CVE-2026-15464MEDIUM6.4The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Att...
CVE-2026-15334MEDIUM6.4The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress...
CVE-2026-15333MEDIUM6.4The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress...
CVE-2026-12654MEDIUM5.3The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up...
CVE-2026-14603HIGH7.5The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint...
CVE-2026-14172HIGH7.8Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without ...
CVE-2026-12981HIGH7.5The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user pas...
CVE-2026-12877CRITICAL9.1The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user s...
CVE-2026-12690LOW3.8The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, ...
CVE-2026-12689MEDIUM5.4The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its pr...
CVE-2026-12688MEDIUM6.5The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group mem...
CVE-2026-12497HIGH7.5The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...
CVE-2026-16870HIGH8.8Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execut...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now