2026 CVE Vulnerabilities
57,011 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14453 | CRITICAL | 9.6 | 0.5% | Jul 13, 2026 | This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that l... |
| CVE-2026-10106 | MEDIUM | 6.5 | 0.2% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced i... |
| CVE-2026-10103 | MEDIUM | 4.3 | 0.1% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared ... |
| CVE-2026-10085 | MEDIUM | 5.4 | 0.2% | Jul 13, 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained chann... |
| CVE-2026-57830 | CRITICAL | 9.1 | 0.2% | Jul 13, 2026 | Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla exten... |
| CVE-2026-57829 | MEDIUM | 6.1 | 0.1% | Jul 13, 2026 | Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ul... |
| CVE-2026-4769 | CRITICAL | 9.8 | 0.4% | Jul 13, 2026 | Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startu... |
| CVE-2026-15544 | HIGH | 8.8 | 0.4% | Jul 13, 2026 | A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcu... |
| CVE-2026-15543 | HIGH | 8.8 | 0.5% | Jul 13, 2026 | A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertList... |
| CVE-2026-15542 | HIGH | 7.3 | 0.4% | Jul 13, 2026 | A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.g... |
| CVE-2026-15541 | HIGH | 7.3 | 0.3% | Jul 13, 2026 | A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file a... |
| CVE-2026-15540 | MEDIUM | 4.3 | 0.2% | Jul 13, 2026 | A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function... |
| CVE-2026-14165 | HIGH | 7.5 | 0.2% | Jul 13, 2026 | An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through ... |
| CVE-2026-15539 | MEDIUM | 4.7 | 0.2% | Jul 13, 2026 | A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown functi... |
| CVE-2026-15538 | MEDIUM | 6.3 | 0.4% | Jul 13, 2026 | A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutate... |
| CVE-2026-15537 | HIGH | 7.3 | 0.3% | Jul 13, 2026 | A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown c... |
| CVE-2026-15536 | MEDIUM | 6.3 | 0.2% | Jul 13, 2026 | A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file ... |
| CVE-2026-12582 | HIGH | 8.6 | 0.2% | Jul 13, 2026 | The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter befor... |
| CVE-2026-12397 | MEDIUM | 4.3 | 0.1% | Jul 13, 2026 | The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email fo... |
| CVE-2026-12396 | MEDIUM | 5.4 | 0.1% | Jul 13, 2026 | The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job mod... |
| CVE-2026-12275 | HIGH | 7.1 | 0.1% | Jul 13, 2026 | The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enr... |
| CVE-2026-12274 | MEDIUM | 6.5 | 0.1% | Jul 13, 2026 | The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post ... |
| CVE-2026-12273 | MEDIUM | 4.3 | 0.1% | Jul 13, 2026 | The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creati... |
| CVE-2026-12271 | MEDIUM | 5.4 | 0.1% | Jul 13, 2026 | The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to i... |
| CVE-2026-12081 | MEDIUM | 5 | 0.2% | Jul 13, 2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classe... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now