2026 CVE Vulnerabilities
53,393 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24961 | MEDIUM | 5.4 | 0.2% | Feb 3, 2026 | Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Server Side Request Forgery.T... |
| CVE-2026-24958 | MEDIUM | 6.5 | 0.2% | Feb 3, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElem... |
| CVE-2026-24957 | MEDIUM | 6.5 | 0.2% | Feb 3, 2026 | Missing Authorization vulnerability in WP Chill Strong Testimonials strong-testimonials allows Exploiting Incorrectly Co... |
| CVE-2026-24952 | MEDIUM | 6.5 | 0.2% | Feb 3, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Craig Hewitt Serio... |
| CVE-2026-24951 | MEDIUM | 4.3 | 0.2% | Feb 3, 2026 | Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-24947 | MEDIUM | 4.3 | 0.2% | Feb 3, 2026 | Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploit... |
| CVE-2026-24945 | MEDIUM | 5.3 | 0.2% | Feb 3, 2026 | Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 al... |
| CVE-2026-24942 | MEDIUM | 4.3 | 0.1% | Feb 3, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in magepeopleteam WpEvently mage-eventpress allows Cross Site Request Fo... |
| CVE-2026-24940 | MEDIUM | 4.3 | 0.2% | Feb 3, 2026 | Missing Authorization vulnerability in Themefic Travelfic Toolkit travelfic-toolkit allows Exploiting Incorrectly Config... |
| CVE-2026-24939 | MEDIUM | 4.3 | 0.2% | Feb 3, 2026 | Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Exploiting Incorrec... |
| CVE-2026-24938 | MEDIUM | 5.9 | 0.2% | Feb 3, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Better Search... |
| CVE-2026-1814 | MEDIUM | 6.8 | 0.1% | Feb 3, 2026 | Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassw... |
| CVE-2026-1312 | MEDIUM | 5.4 | 0.8% | Feb 3, 2026 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `.QuerySet.order_by()` is subject... |
| CVE-2026-1287 | MEDIUM | 5.4 | 0.8% | Feb 3, 2026 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `FilteredRelation` is subject to ... |
| CVE-2026-1207 | MEDIUM | 5.4 | 9.4% | Feb 3, 2026 | An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. Raster lookups on ``RasterField``... |
| CVE-2026-1664 | MEDIUM | 6.9 | 0.4% | Feb 3, 2026 | Summary An Insecure Direct Object Reference has been found to exist in `createHeaderBasedEmailResolver()` function with... |
| CVE-2026-1592 | MEDIUM | 5.4 | 0.2% | Feb 3, 2026 | Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the Create New Layer feature.... |
| CVE-2026-1591 | MEDIUM | 5.4 | 0.2% | Feb 3, 2026 | Foxit PDF Editor Cloud (pdfonline) contains a stored cross-site scripting vulnerability in the file upload feature. A ma... |
| CVE-2026-1371 | MEDIUM | 5.3 | 0.3% | Feb 3, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Sensitive Information Exposur... |
| CVE-2026-24449 | MEDIUM | 5.1 | 0.2% | Feb 3, 2026 | For WRC-X1500GS-B and WRC-X1500GSA-B, the initial passwords can be calculated easily from the system information. |
| CVE-2026-20704 | MEDIUM | 5.1 | 0.1% | Feb 3, 2026 | Cross-site request forgery vulnerability exists in ELECOM wireless LAN products. If a user accesses a malicious page whi... |
| CVE-2026-1447 | MEDIUM | 5.4 | 0.2% | Feb 3, 2026 | The Mail Mint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1... |
| CVE-2026-1210 | MEDIUM | 6.4 | 0.3% | Feb 3, 2026 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_elementor_dat... |
| CVE-2026-0950 | MEDIUM | 5.3 | 0.3% | Feb 3, 2026 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Di... |
| CVE-2026-1788 | MEDIUM | 6.6 | 0.4% | Feb 3, 2026 | : Out-of-bounds Write vulnerability in Xquic Project Xquic Server xquic on Linux (QUIC protocol implementation, packet p... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now