2026 CVE Vulnerabilities
53,582 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1004 | MEDIUM | 5.3 | 0.3% | Jan 16, 2026 | The Essential Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ... |
| CVE-2026-0913 | MEDIUM | 6.4 | 0.2% | Jan 16, 2026 | The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored ... |
| CVE-2026-1003 | MEDIUM | 4.3 | 0.2% | Jan 16, 2026 | The GetGenie plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.0. Thi... |
| CVE-2026-0942 | MEDIUM | 5.3 | 0.3% | Jan 16, 2026 | The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit plugin for WordPress is vulnerable to unauthorized mo... |
| CVE-2026-0939 | MEDIUM | 5.3 | 0.1% | Jan 16, 2026 | The Rede Itaú for WooCommerce plugin for WordPress is vulnerable to order status manipulation due to insufficient verifi... |
| CVE-2026-0916 | MEDIUM | 6.4 | 0.2% | Jan 16, 2026 | The Related Posts by Taxonomy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'relate... |
| CVE-2026-23769 | MEDIUM | 6.1 | 0.2% | Jan 16, 2026 | lucy-xss-filter before commit e5826c0 allows an attacker to execute malicious JavaScript due to improper sanitization ca... |
| CVE-2026-23768 | MEDIUM | 6.1 | 0.2% | Jan 16, 2026 | lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ... |
| CVE-2026-1000 | MEDIUM | 6.5 | 0.3% | Jan 16, 2026 | The MailerLite - WooCommerce integration plugin for WordPress is vulnerable to unauthorized data modification and deleti... |
| CVE-2026-0858 | MEDIUM | 6.1 | 0.3% | Jan 16, 2026 | Versions of the package net.sourceforge.plantuml:plantuml before 1.2026.0 are vulnerable to Stored XSS due to insufficie... |
| CVE-2026-1011 | MEDIUM | 6.1 | 0.3% | Jan 16, 2026 | A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing... |
| CVE-2026-1010 | MEDIUM | 5.4 | 0.3% | Jan 15, 2026 | A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input ... |
| CVE-2026-1009 | MEDIUM | 5.4 | 0.2% | Jan 15, 2026 | A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitizati... |
| CVE-2026-1008 | MEDIUM | 5.4 | 0.2% | Jan 15, 2026 | A stored cross-site scripting (XSS) vulnerability exists in the user profile text fields of Altium 365. Insufficient ser... |
| CVE-2026-21912 | MEDIUM | 4.7 | 0.1% | Jan 15, 2026 | A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the method to collect FPC Ethernet firmware statist... |
| CVE-2026-1002 | MEDIUM | 5.3 | 0.3% | Jan 15, 2026 | The Vert.x Web static handler component cache can be manipulated to deny the access to static files served by the handle... |
| CVE-2026-23511 | MEDIUM | 5.3 | 0.4% | Jan 15, 2026 | ZITADEL is an open source identity management platform. Prior to 4.9.1 and 3.4.6, a user enumeration vulnerability has b... |
| CVE-2026-23496 | MEDIUM | 5.4 | 0.3% | Jan 15, 2026 | Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the applicati... |
| CVE-2026-23495 | MEDIUM | 4.3 | 0.3% | Jan 15, 2026 | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listin... |
| CVE-2026-23494 | MEDIUM | 6.5 | 0.3% | Jan 15, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the application fails to e... |
| CVE-2026-23493 | MEDIUM | 4.9 | 0.4% | Jan 15, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file st... |
| CVE-2026-22867 | MEDIUM | 5.4 | 0.3% | Jan 15, 2026 | LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 3.8.0 to 4.3.0, a Stored Cross-Site Sc... |
| CVE-2026-20076 | MEDIUM | 4.8 | 0.2% | Jan 15, 2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2026-20075 | MEDIUM | 4.8 | 0.2% | Jan 15, 2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Pri... |
| CVE-2026-20047 | MEDIUM | 4.8 | 0.2% | Jan 15, 2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Iden... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now