2026 CVE Vulnerabilities
57,021 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15295 | MEDIUM | 4.4 | 0.2% | Jul 10, 2026 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm... |
| CVE-2026-11321 | HIGH | 7.1 | 0.3% | Jul 10, 2026 | The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL ... |
| CVE-2026-6872 | — | — | — | Jul 10, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-6212 | HIGH | 8.8 | — | Jul 10, 2026 | Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Pri... |
| CVE-2026-61461 | HIGH | 8.8 | 0.4% | Jul 10, 2026 | Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers ... |
| CVE-2026-61460 | HIGH | 8.8 | — | Jul 10, 2026 | Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController,... |
| CVE-2026-61459 | CRITICAL | 9.8 | 0.4% | Jul 10, 2026 | MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubect... |
| CVE-2026-5801 | CRITICAL | 9.8 | — | Jul 10, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics... |
| CVE-2026-59151 | CRITICAL | 9.6 | 0.5% | Jul 10, 2026 | Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asser... |
| CVE-2026-55843 | MEDIUM | 6.5 | 0.3% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission... |
| CVE-2026-55516 | HIGH | 7.7 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} ch... |
| CVE-2026-55478 | MEDIUM | 5.4 | — | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether th... |
| CVE-2026-55476 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.0, POST /account/request/{itemType}/{itemId}/{cancel_by_... |
| CVE-2026-55474 | MEDIUM | 6.5 | — | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the rout... |
| CVE-2026-55472 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, when Full Multiple Companies Support and scope_locati... |
| CVE-2026-55464 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize jav... |
| CVE-2026-55460 | HIGH | 7.1 | 0.3% | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and u... |
| CVE-2026-54329 | HIGH | 7.7 | — | Jul 10, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request ... |
| CVE-2026-53450 | HIGH | 7.4 | 0.3% | Jul 10, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, coturn rejects loopback peers by d... |
| CVE-2026-53449 | MEDIUM | 6 | 0.2% | Jul 10, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, the psd print sessions dump CLI co... |
| CVE-2026-53448 | HIGH | 7.2 | 0.7% | Jul 10, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.12.0, the coturn HTTPS admin panel passe... |
| CVE-2026-15146 | MEDIUM | 5.9 | 0.1% | Jul 10, 2026 | GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malici... |
| CVE-2026-57476 | MEDIUM | 6.3 | 0.3% | Jul 10, 2026 | Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additio... |
| CVE-2026-57475 | MEDIUM | 6.9 | 0.3% | Jul 10, 2026 | Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed ... |
| CVE-2026-57474 | MEDIUM | 6.9 | 0.3% | Jul 10, 2026 | Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accept... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now