2026 CVE Vulnerabilities
57,056 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12879 | MEDIUM | 5.9 | — | Jul 9, 2026 | An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google... |
| CVE-2026-12593 | HIGH | 8.7 | 0.3% | Jul 9, 2026 | The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to en... |
| CVE-2026-12116 | CRITICAL | 9.8 | — | Jul 9, 2026 | A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings,... |
| CVE-2026-15184 | LOW | 3.3 | — | Jul 9, 2026 | A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file... |
| CVE-2026-9253 | HIGH | 7.2 | — | Jul 9, 2026 | The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scrip... |
| CVE-2026-15182 | MEDIUM | 5.3 | — | Jul 9, 2026 | A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file sr... |
| CVE-2026-9240 | MEDIUM | 4.3 | — | Jul 9, 2026 | The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2026-9237 | MEDIUM | 4.3 | — | Jul 9, 2026 | The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization byp... |
| CVE-2026-9235 | MEDIUM | 4.3 | — | Jul 9, 2026 | The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of ... |
| CVE-2026-9028 | MEDIUM | 5.3 | — | Jul 9, 2026 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up ... |
| CVE-2026-9027 | MEDIUM | 5.3 | — | Jul 9, 2026 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification... |
| CVE-2026-9021 | MEDIUM | 5.3 | — | Jul 9, 2026 | The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. T... |
| CVE-2026-59692 | HIGH | 7.5 | 0.6% | Jul 9, 2026 | A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificat... |
| CVE-2026-59691 | HIGH | 7.1 | 0.3% | Jul 9, 2026 | A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/V... |
| CVE-2026-58307 | MEDIUM | 6.1 | — | Jul 9, 2026 | Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Dat... |
| CVE-2026-58306 | MEDIUM | 6.1 | — | Jul 9, 2026 | Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Es... |
| CVE-2026-58305 | MEDIUM | 6.1 | — | Jul 9, 2026 | Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Point... |
| CVE-2026-58304 | MEDIUM | 6.1 | — | Jul 9, 2026 | Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This iss... |
| CVE-2026-58303 | MEDIUM | 6.1 | — | Jul 9, 2026 | Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects E... |
| CVE-2026-56291 | CRITICAL | 9.8 | 8.6% | Jul 9, 2026 | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension B... |
| CVE-2026-56289 | MEDIUM | 5.5 | 0.1% | Jul 9, 2026 | GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff... |
| CVE-2026-56288 | MEDIUM | 5.5 | 0.1% | Jul 9, 2026 | GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Impro... |
| CVE-2026-50644 | HIGH | 8.6 | — | Jul 9, 2026 | SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all right... |
| CVE-2026-4298 | MEDIUM | 4.3 | — | Jul 9, 2026 | The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and includ... |
| CVE-2026-4275 | HIGH | 8.8 | — | Jul 9, 2026 | The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request F... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now