2026 CVE Vulnerabilities

53,405 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-4546HIGH7.3A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextSha...
CVE-2026-4545HIGH7.3A security flaw has been discovered in Flos Freeware Notepad2 4.2.25. This affects an unknown function in the library PR...
CVE-2026-4540HIGH7.3A vulnerability was detected in projectworlds Online Notes Sharing System 1.0. This issue affects some unknown processin...
CVE-2026-4538HIGH7.8A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loadi...
CVE-2026-4536HIGH7.3A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. This issue affects some unknown proces...
CVE-2026-4535HIGH8.8A vulnerability has been found in Tenda FH451 1.0.0.9. This vulnerability affects the function WrlclientSet of the file ...
CVE-2026-4534HIGH8.8A flaw has been found in Tenda FH451 1.0.0.9. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet....
CVE-2026-4314HIGH8.8The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all ver...
CVE-2026-4533HIGH8.8A vulnerability was detected in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown fu...
CVE-2026-33549HIGH8.8SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the...
CVE-2026-4532HIGH7.5A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vuln...
CVE-2026-4529HIGH8.8A vulnerability was identified in D-Link DHP-1320 1.00WWB04. This affects the function redirect_count_down_page of the c...
CVE-2026-3629HIGH8.1The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up ...
CVE-2026-4528HIGH7.3A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of th...
CVE-2026-4373HIGH7.5The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, a...
CVE-2026-4261HIGH8.8The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2....
CVE-2026-3478HIGH7.2The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to,...
CVE-2026-3334HIGH8.8The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and '...
CVE-2026-3003HIGH7.2The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parame...
CVE-2026-2941HIGH8.8The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2026-2468HIGH7.5The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions up to,...
CVE-2026-2440HIGH7.2The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5...
CVE-2026-2279HIGH7.2The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all...
CVE-2026-1800HIGH7.5The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSelectedF...
CVE-2026-1648HIGH7.2The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now