2026 CVE Vulnerabilities

42,999 CVEs published in 2026.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2026-68868The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re...
CVE-2026-19566Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix ...
CVE-2026-19217The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTM...
CVE-2026-18391The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stor...
CVE-2026-18366The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access ...
CVE-2026-18230The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta...
CVE-2026-18057The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it i...
CVE-2026-18049The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its ...
CVE-2026-18048The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a f...
CVE-2026-18046The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability...
CVE-2026-18035The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allo...
CVE-2026-17013The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it...
CVE-2026-16977The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is ...
CVE-2026-16737The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a ca...
CVE-2026-16538The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top...
CVE-2026-16294The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode...
CVE-2026-16253The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-resto...
CVE-2026-16066The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it ...
CVE-2026-16051The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its re...
CVE-2026-15388The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability...
CVE-2026-15249The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts i...
CVE-2026-15039The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, all...
CVE-2026-14925The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file downlo...
CVE-2026-14859The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX a...
CVE-2026-14858The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now