2026 CVE Vulnerabilities

64,824 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-27559HIGH8.8A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sendi...
CVE-2026-27558HIGH8.8A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/aj...
CVE-2026-27557HIGH7.5An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file ...
CVE-2026-27556HIGH8.8A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_param...
CVE-2026-27555HIGH8.8A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_i...
CVE-2026-27554HIGH8.8A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_paramete...
CVE-2026-27552HIGH8.1A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload end...
CVE-2026-27551HIGH8.8A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage en...
CVE-2026-27550HIGH8.8A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using ...
CVE-2026-27549HIGH8.8A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do...
CVE-2026-27548HIGH8.8A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info...
CVE-2026-27547HIGH8.8A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info...
CVE-2026-79708HIGH8.5GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3...
CVE-2026-78252HIGH8.2GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 1...
CVE-2026-1168HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and...
CVE-2026-19248HIGH7.1QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input...
CVE-2026-86444HIGH7.1The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute...
CVE-2026-85569HIGH7.2The Tutor LMS WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addressed to it...
CVE-2026-85530HIGH8.1The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value ...
CVE-2026-84829HIGH8.8The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an ...
CVE-2026-78472HIGH8.6The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it ...
CVE-2026-76552HIGH8.8The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it re...
CVE-2026-76551HIGH7.2The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported...
CVE-2026-76550HIGH7.2The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing expo...
CVE-2026-74926HIGH7.1The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now