2026 CVE Vulnerabilities
53,405 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4546 | HIGH | 7.3 | 0.2% | Mar 22, 2026 | A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextSha... |
| CVE-2026-4545 | HIGH | 7.3 | 0.1% | Mar 22, 2026 | A security flaw has been discovered in Flos Freeware Notepad2 4.2.25. This affects an unknown function in the library PR... |
| CVE-2026-4540 | HIGH | 7.3 | 0.4% | Mar 22, 2026 | A vulnerability was detected in projectworlds Online Notes Sharing System 1.0. This issue affects some unknown processin... |
| CVE-2026-4538 | HIGH | 7.8 | 0.2% | Mar 22, 2026 | A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loadi... |
| CVE-2026-4536 | HIGH | 7.3 | 0.3% | Mar 22, 2026 | A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. This issue affects some unknown proces... |
| CVE-2026-4535 | HIGH | 8.8 | 0.6% | Mar 22, 2026 | A vulnerability has been found in Tenda FH451 1.0.0.9. This vulnerability affects the function WrlclientSet of the file ... |
| CVE-2026-4534 | HIGH | 8.8 | 0.6% | Mar 22, 2026 | A flaw has been found in Tenda FH451 1.0.0.9. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet.... |
| CVE-2026-4314 | HIGH | 8.8 | 0.3% | Mar 22, 2026 | The 'The Ultimate WordPress Toolkit – WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all ver... |
| CVE-2026-4533 | HIGH | 8.8 | 0.3% | Mar 22, 2026 | A vulnerability was detected in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown fu... |
| CVE-2026-33549 | HIGH | 8.8 | 0.2% | Mar 22, 2026 | SPIP 4.4.10 through 4.4.12 before 4.4.13 allows unintended privilege assignment (of administrator privileges) during the... |
| CVE-2026-4532 | HIGH | 7.5 | 0.5% | Mar 22, 2026 | A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vuln... |
| CVE-2026-4529 | HIGH | 8.8 | 0.7% | Mar 21, 2026 | A vulnerability was identified in D-Link DHP-1320 1.00WWB04. This affects the function redirect_count_down_page of the c... |
| CVE-2026-3629 | HIGH | 8.1 | 0.4% | Mar 21, 2026 | The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up ... |
| CVE-2026-4528 | HIGH | 7.3 | 0.3% | Mar 21, 2026 | A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of th... |
| CVE-2026-4373 | HIGH | 7.5 | 0.4% | Mar 21, 2026 | The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, a... |
| CVE-2026-4261 | HIGH | 8.8 | 0.3% | Mar 21, 2026 | The Expire Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.2.... |
| CVE-2026-3478 | HIGH | 7.2 | 0.3% | Mar 21, 2026 | The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to,... |
| CVE-2026-3334 | HIGH | 8.8 | 0.3% | Mar 21, 2026 | The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and '... |
| CVE-2026-3003 | HIGH | 7.2 | 0.3% | Mar 21, 2026 | The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parame... |
| CVE-2026-2941 | HIGH | 8.8 | 0.3% | Mar 21, 2026 | The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2026-2468 | HIGH | 7.5 | 0.4% | Mar 21, 2026 | The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions up to,... |
| CVE-2026-2440 | HIGH | 7.2 | 0.3% | Mar 21, 2026 | The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5... |
| CVE-2026-2279 | HIGH | 7.2 | 0.4% | Mar 21, 2026 | The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all... |
| CVE-2026-1800 | HIGH | 7.5 | 0.4% | Mar 21, 2026 | The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSelectedF... |
| CVE-2026-1648 | HIGH | 7.2 | 0.4% | Mar 21, 2026 | The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now