2026 CVE Vulnerabilities
53,457 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24595 | MEDIUM | 5.4 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows Exploiting Incorrectly Configu... |
| CVE-2026-24594 | MEDIUM | 5.9 | 0.2% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh ... |
| CVE-2026-24593 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Strategy11 Team AWP Classifi... |
| CVE-2026-24591 | MEDIUM | 6.5 | 0.2% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yasir129 Turn Yoas... |
| CVE-2026-24589 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Cargus eCommerce Cargus cargus allows Retrieve Embedd... |
| CVE-2026-24588 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in topdevs Smart Product Viewer smart-product-viewer allows Exploiting Incorrectly C... |
| CVE-2026-24587 | MEDIUM | 5.4 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in kutsy AJAX Hits Counter + Popular Posts Widget ajax-hits-counter allows Exploitin... |
| CVE-2026-24585 | MEDIUM | 6.5 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Hyyan Abo Fakher Hyyan WooCommerce Polylang Integration woo-poly-integration allo... |
| CVE-2026-24584 | MEDIUM | 5.9 | 0.2% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeum Tutor LMS ... |
| CVE-2026-24583 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in sumup SumUp Payment Gateway For WooCommerce sumup-payment-gateway-for-woocommerce... |
| CVE-2026-24581 | MEDIUM | 5.4 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce points-and-rewards-for-woocommerce a... |
| CVE-2026-24580 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Ecwid by Lightspeed Ecommerce Shopping Cart Ecwid Shopping Cart ecwid-shopping-ca... |
| CVE-2026-24579 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in WP Messiah Ai Image Alt Text Generator for WP ai-image-alt-text-generator-for-wp ... |
| CVE-2026-24578 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Jahid Hasan Admin login URL Change admin-login-url-change allows Exploiting Incor... |
| CVE-2026-24577 | MEDIUM | 5.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Genetech Products Pie Register pie-register allows Exploiting Incorrectly Configu... |
| CVE-2026-24576 | MEDIUM | 6.5 | 0.2% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in COP UX Flat ux-fla... |
| CVE-2026-24571 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in boxnow BOX NOW Delivery box-now-delivery allows Exploiting Incorrectly Configured... |
| CVE-2026-24570 | MEDIUM | 5.4 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in WisdmLabs Edwiser Bridge edwiser-bridge allows Exploiting Incorrectly Configured ... |
| CVE-2026-24569 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Sully Media Library File Size media-library-file-size allows Exploiting Incorrect... |
| CVE-2026-24568 | MEDIUM | 5.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in WP Travel WP Travel wp-travel allows Exploiting Incorrectly Configured Access Con... |
| CVE-2026-24567 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in briarinc Anything Order by Terms anything-order-by-terms allows Exploiting Incorr... |
| CVE-2026-24566 | MEDIUM | 6.5 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in iNET iNET Webkit inet-webkit allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2026-24565 | MEDIUM | 6.5 | 0.3% | Jan 23, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in bPlugins B Accordion b-accordion allows Retrieve Embe... |
| CVE-2026-24564 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Israpil Textmetrics webte... |
| CVE-2026-24563 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Ashan Perera LifePress lifepress allows Exploiting Incorrectly Configured Access ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now