2026 CVE Vulnerabilities
53,211 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23548 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in Designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configu... |
| CVE-2026-23545 | MEDIUM | 6.5 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in Aruba.it Dev Aruba HiSpeed Cache aruba-hispeed-cache allows Exploiting Incorrectl... |
| CVE-2026-23543 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite al... |
| CVE-2026-22422 | MEDIUM | 5.3 | 0.2% | Feb 19, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in wpeverest Everest Forms e... |
| CVE-2026-22269 | MEDIUM | 4.7 | 0.2% | Feb 19, 2026 | Dell PowerProtect Data Manager, version(s) prior to 19.22, contain(s) an Improper Verification of Source of a Communicat... |
| CVE-2026-2711 | MEDIUM | 5.6 | 0.4% | Feb 19, 2026 | A vulnerability has been found in zhutoutoutousan worldquant-miner up to 1.0.9. The impacted element is an unknown funct... |
| CVE-2026-2703 | MEDIUM | 5.5 | 0.2% | Feb 19, 2026 | A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::decode_base64 ... |
| CVE-2026-2693 | MEDIUM | 6.5 | 0.4% | Feb 19, 2026 | A vulnerability was determined in CoCoTeaNet CyreneAdmin up to 1.3.0. This vulnerability affects unknown code of the fil... |
| CVE-2026-2692 | MEDIUM | 6.5 | 0.5% | Feb 19, 2026 | A vulnerability was found in CoCoTeaNet CyreneAdmin up to 1.3.0. This affects an unknown part of the file /api/system/us... |
| CVE-2026-2681 | MEDIUM | 5.3 | 0.3% | Feb 19, 2026 | A flaw was found in the blst cryptographic library. This out-of-bounds stack write vulnerability, specifically in the bl... |
| CVE-2026-2504 | MEDIUM | 4.3 | 0.2% | Feb 19, 2026 | The Dealia – Request a quote plugin for WordPress is vulnerable to unauthorized modification of data due to missing capa... |
| CVE-2026-2502 | MEDIUM | 6.1 | 0.3% | Feb 19, 2026 | The xmlrpc attacks blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl... |
| CVE-2026-2284 | MEDIUM | 5.4 | 0.2% | Feb 19, 2026 | The News Element Elementor Blog Magazine plugin for WordPress is vulnerable to Missing Authorization in all versions up ... |
| CVE-2026-2282 | MEDIUM | 4.4 | 0.2% | Feb 19, 2026 | The Slidorion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to... |
| CVE-2026-25229 | MEDIUM | 6.5 | 0.3% | Feb 19, 2026 | Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have a broken access control vulnerability whi... |
| CVE-2026-1646 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | The Advance Block Extend plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TitleColor block attr... |
| CVE-2026-1455 | MEDIUM | 4.3 | 0.1% | Feb 19, 2026 | The Whatsiplus Scheduled Notification for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2026-1373 | MEDIUM | 6.4 | 0.2% | Feb 19, 2026 | The Easy Author Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author_profile_picture_... |
| CVE-2026-1055 | MEDIUM | 4.4 | 0.2% | Feb 19, 2026 | The TalkJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, a... |
| CVE-2026-1047 | MEDIUM | 4.4 | 0.3% | Feb 19, 2026 | The salavat counter Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_url' paramet... |
| CVE-2026-1044 | MEDIUM | 4.4 | 0.3% | Feb 19, 2026 | The Tennis Court Bookings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ve... |
| CVE-2026-1043 | MEDIUM | 4.4 | 0.2% | Feb 19, 2026 | The PostmarkApp Email Integrator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settin... |
| CVE-2026-0722 | MEDIUM | 6.5 | 0.4% | Feb 19, 2026 | The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2026-0561 | MEDIUM | 6.1 | 0.3% | Feb 19, 2026 | The Shield Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in ... |
| CVE-2026-0556 | MEDIUM | 6.4 | 0.3% | Feb 19, 2026 | The XO Event Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xo_event_field... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now