2026 CVE Vulnerabilities
57,035 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41876 | HIGH | 8.7 | 1.2% | Jul 10, 2026 | R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell co... |
| CVE-2026-15378 | CRITICAL | 9.3 | 0.5% | Jul 10, 2026 | A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind... |
| CVE-2026-15028 | LOW | 3.9 | 0.3% | Jul 10, 2026 | A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a sp... |
| CVE-2026-13710 | MEDIUM | 6.4 | 0.4% | Jul 10, 2026 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul... |
| CVE-2026-13247 | MEDIUM | 6.4 | 0.3% | Jul 10, 2026 | The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to... |
| CVE-2026-13010 | MEDIUM | 6.5 | 0.4% | Jul 10, 2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL ... |
| CVE-2026-12918 | MEDIUM | 4.9 | 0.3% | Jul 10, 2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to... |
| CVE-2026-11990 | MEDIUM | 5.3 | 0.6% | Jul 10, 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in al... |
| CVE-2026-9838 | MEDIUM | 6.1 | 0.3% | Jul 10, 2026 | The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter i... |
| CVE-2026-6802 | MEDIUM | 5.3 | 0.2% | Jul 10, 2026 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, a... |
| CVE-2026-6440 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cro... |
| CVE-2026-3907 | MEDIUM | 6.4 | 0.2% | Jul 10, 2026 | The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all ve... |
| CVE-2026-1946 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2026-15104 | MEDIUM | 6.5 | 0.3% | Jul 10, 2026 | The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to g... |
| CVE-2026-15026 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve... |
| CVE-2026-14475 | MEDIUM | 4.9 | 0.3% | Jul 10, 2026 | The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via ... |
| CVE-2026-12955 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil... |
| CVE-2026-12924 | MEDIUM | 6.4 | 0.2% | Jul 10, 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to S... |
| CVE-2026-12400 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in al... |
| CVE-2026-12108 | MEDIUM | 4.4 | 0.2% | Jul 10, 2026 | The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ... |
| CVE-2026-11992 | MEDIUM | 4.3 | 0.3% | Jul 10, 2026 | The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3... |
| CVE-2026-40454 | HIGH | 7.5 | 0.1% | Jul 10, 2026 | Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++... |
| CVE-2026-40452 | HIGH | 7.5 | 0.1% | Jul 10, 2026 | Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLas... |
| CVE-2026-40009 | MEDIUM | 6.5 | 0.1% | Jul 10, 2026 | Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate t... |
| CVE-2026-40008 | CRITICAL | 9.8 | 0.3% | Jul 10, 2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The pi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now