2026 CVE Vulnerabilities
53,212 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1304 | MEDIUM | 4.4 | 0.3% | Feb 18, 2026 | The Membership Plugin – Restrict Content for WordPress is vulnerable to Stored Cross-Site Scripting via multiple invoice... |
| CVE-2026-1072 | MEDIUM | 4.3 | 0.2% | Feb 18, 2026 | The Keybase.io Verification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2026-1925 | MEDIUM | 4.3 | 0.2% | Feb 18, 2026 | The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to unauthorized data modificatio... |
| CVE-2026-1296 | MEDIUM | 6.1 | 0.5% | Feb 18, 2026 | The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, ... |
| CVE-2026-1277 | MEDIUM | 4.7 | 0.6% | Feb 18, 2026 | The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to... |
| CVE-2026-27171 | MEDIUM | 5.5 | 0.2% | Feb 18, 2026 | zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts... |
| CVE-2026-1344 | MEDIUM | 5.5 | 0.1% | Feb 18, 2026 | Tanium addressed an insecure file permissions vulnerability in Enforce Recovery Key Portal. |
| CVE-2026-2622 | MEDIUM | 5.4 | 0.3% | Feb 17, 2026 | A vulnerability was detected in Blossom up to 1.17.1. This vulnerability affects the function content of the file blosso... |
| CVE-2026-23598 | MEDIUM | 6.5 | 0.3% | Feb 17, 2026 | Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated ... |
| CVE-2026-23597 | MEDIUM | 6.5 | 0.2% | Feb 17, 2026 | Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated ... |
| CVE-2026-23596 | MEDIUM | 6.5 | 0.2% | Feb 17, 2026 | A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger ... |
| CVE-2026-26357 | MEDIUM | 5.4 | 0.2% | Feb 17, 2026 | Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Input During Web Page Generati... |
| CVE-2026-22762 | MEDIUM | 6.5 | 0.3% | Feb 17, 2026 | Dell Avamar Server and Avamar Virtual Edition, versions prior to 19.10 SP1 with CHF338912, contain an Improper Limitatio... |
| CVE-2026-23861 | MEDIUM | 5.4 | 0.2% | Feb 17, 2026 | Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Input During Web Page Gen... |
| CVE-2026-2608 | MEDIUM | 4.3 | 0.2% | Feb 17, 2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access... |
| CVE-2026-25903 | MEDIUM | 6.6 | 0.8% | Feb 17, 2026 | Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components... |
| CVE-2026-0829 | MEDIUM | 5.8 | 0.7% | Feb 17, 2026 | The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the s... |
| CVE-2026-1657 | MEDIUM | 5.3 | 0.4% | Feb 17, 2026 | The EventPrime plugin for WordPress is vulnerable to unauthorized image file upload in all versions up to, and including... |
| CVE-2026-2002 | MEDIUM | 4.4 | 0.2% | Feb 17, 2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2026-2565 | MEDIUM | 6.6 | 0.8% | Feb 16, 2026 | A weakness has been identified in Wavlink WL-NU516U1 20251208. Affected by this issue is the function sub_40785C of the ... |
| CVE-2026-2032 | MEDIUM | 4.3 | 0.1% | Feb 16, 2026 | Malicious scripts that interrupt new tab page loading could cause desynchronization between the address bar and page con... |
| CVE-2026-2560 | MEDIUM | 6.3 | 1.7% | Feb 16, 2026 | A vulnerability has been found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file p... |
| CVE-2026-2558 | MEDIUM | 6.3 | 0.2% | Feb 16, 2026 | A flaw has been found in GeekAI up to 4.2.4. The affected element is the function Download of the file api/handler/net_h... |
| CVE-2026-2557 | MEDIUM | 5.4 | 0.2% | Feb 16, 2026 | A vulnerability was detected in cskefu up to 8.0.1. Impacted is the function Upload of the file com/cskefu/cc/controller... |
| CVE-2026-2556 | MEDIUM | 6.3 | 0.3% | Feb 16, 2026 | A security vulnerability has been detected in cskefu up to 8.0.1. This issue affects some unknown processing of the file... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now