2026 CVE Vulnerabilities
53,500 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24542 | MEDIUM | 4.3 | 0.1% | Jan 23, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in John James Jacoby WP Term Order wp-term-order allows Cross Site Reque... |
| CVE-2026-24541 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in mkscripts Download After Email download-after-email allows Exploiting Incorrectly... |
| CVE-2026-24540 | MEDIUM | 5.4 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in princeahmed Integrate Google Drive integrate-google-drive allows Exploiting Incor... |
| CVE-2026-24539 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in ABCdatos Protección de datos – RGPD proteccion-datos-rgpd allows Exploiting Incor... |
| CVE-2026-24536 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in webpushr Webpushr webpushr-w... |
| CVE-2026-24535 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in webdevstudios Automatic Featured Images from Videos automatic-featured-images-fro... |
| CVE-2026-24534 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in uPress Booter booter-bots-crawlers-manager allows Exploiting Incorrectly Configur... |
| CVE-2026-24532 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in SiteLock SiteLock Security – WP Hardening, Login Security & Malware Scans siteloc... |
| CVE-2026-24530 | MEDIUM | 5.3 | 0.4% | Jan 23, 2026 | Missing Authorization vulnerability in sheepfish WebP Conversion webp-conversion allows Exploiting Incorrectly Configure... |
| CVE-2026-24529 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in Alejandro Quick Restaurant Reservations quick-restaurant-reservations allows Expl... |
| CVE-2026-24528 | MEDIUM | 6.5 | 0.2% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Nova Bl... |
| CVE-2026-24526 | MEDIUM | 6.5 | 0.2% | Jan 23, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve Truman Email... |
| CVE-2026-24525 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Missing Authorization vulnerability in CloudPanel CLP Varnish Cache clp-varnish-cache allows Exploiting Incorrectly Conf... |
| CVE-2026-24524 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2026-24523 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Marcus (aka @msykes) WP Full... |
| CVE-2026-24522 | MEDIUM | 4.3 | 0.2% | Jan 23, 2026 | Missing Authorization vulnerability in MyThemeShop WP Subscribe wp-subscribe allows Exploiting Incorrectly Configured Ac... |
| CVE-2026-24521 | MEDIUM | 4.3 | 0.1% | Jan 23, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Timur Kamaev Kama Thumbnail kama-thumbnail allows Cross Site Request ... |
| CVE-2026-0914 | MEDIUM | 6.4 | 0.3% | Jan 23, 2026 | The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lw_content... |
| CVE-2026-22276 | MEDIUM | 5.5 | 0.1% | Jan 23, 2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage... |
| CVE-2026-22275 | MEDIUM | 4.4 | 0.1% | Jan 23, 2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Inclusion of Sen... |
| CVE-2026-22274 | MEDIUM | 6.5 | 0.2% | Jan 23, 2026 | Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Transmi... |
| CVE-2026-0927 | MEDIUM | 5.3 | 0.3% | Jan 23, 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to arbitrary file uploads due... |
| CVE-2026-0788 | MEDIUM | 6.1 | 0.4% | Jan 23, 2026 | ALGO 8180 IP Audio Alerter Web UI Persistent Cross-Site Scripting Vulnerability. This vulnerability allows remote attack... |
| CVE-2026-24137 | MEDIUM | 5.8 | 0.4% | Jan 23, 2026 | sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the... |
| CVE-2026-24130 | MEDIUM | 5.3 | 0.3% | Jan 22, 2026 | Moonraker is a Python web server providing API access to Klipper 3D printing firmware. In versions 0.9.3 and below, inst... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now