2026 CVE Vulnerabilities
43,347 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14257 | HIGH | 7.5 | — | Jul 23, 2026 | brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the... |
| CVE-2026-65908 | HIGH | 8.6 | 0.1% | Jul 23, 2026 | In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on un... |
| CVE-2026-65897 | HIGH | 8.8 | — | Jul 23, 2026 | Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing au... |
| CVE-2026-65896 | HIGH | 7.1 | — | Jul 23, 2026 | Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in th... |
| CVE-2026-65895 | HIGH | 8.5 | — | Jul 23, 2026 | Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, a... |
| CVE-2026-65608 | HIGH | 8.8 | — | Jul 23, 2026 | Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField()... |
| CVE-2026-65607 | HIGH | 7.1 | 0.4% | Jul 23, 2026 | SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExpor... |
| CVE-2026-65540 | HIGH | 7.1 | — | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions. |
| CVE-2026-65539 | HIGH | 7.1 | — | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. |
| CVE-2026-65532 | HIGH | 7.6 | — | Jul 23, 2026 | Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions. |
| CVE-2026-65526 | HIGH | 8.5 | 0.3% | Jul 23, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualiz... |
| CVE-2026-65516 | HIGH | 7.2 | — | Jul 23, 2026 | Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| CVE-2026-65511 | HIGH | 7.1 | — | Jul 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.... |
| CVE-2026-65510 | HIGH | 7.1 | — | Jul 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. |
| CVE-2026-65500 | HIGH | 7.5 | — | Jul 23, 2026 | Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 ver... |
| CVE-2026-65497 | HIGH | 7.2 | — | Jul 23, 2026 | Administrator PHP Object Injection in Complianz <= 7.5.0 versions. |
| CVE-2026-65495 | HIGH | 7.5 | — | Jul 23, 2026 | Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions. |
| CVE-2026-65494 | HIGH | 7.1 | — | Jul 23, 2026 | Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions. |
| CVE-2026-65493 | HIGH | 7.5 | — | Jul 23, 2026 | Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions. |
| CVE-2026-65492 | HIGH | 7.1 | — | Jul 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions. |
| CVE-2026-65488 | HIGH | 7.1 | — | Jul 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 versions. |
| CVE-2026-65481 | HIGH | 7.5 | — | Jul 23, 2026 | Contributor Local File Inclusion in Vino <= 1.9 versions. |
| CVE-2026-65477 | HIGH | 7.5 | — | Jul 23, 2026 | Contributor Local File Inclusion in Tonda Core <= 2.1.2 versions. |
| CVE-2026-65462 | HIGH | 7.6 | — | Jul 23, 2026 | Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions. |
| CVE-2026-65454 | HIGH | 8.5 | — | Jul 23, 2026 | Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now