2026 CVE Vulnerabilities
57,056 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14372 | HIGH | 7.1 | — | Jul 9, 2026 | The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is v... |
| CVE-2026-13441 | HIGH | 7.2 | — | Jul 9, 2026 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2026-12590 | MEDIUM | 5.9 | — | Jul 9, 2026 | Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an i... |
| CVE-2026-12428 | MEDIUM | 6.5 | — | Jul 9, 2026 | The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ... |
| CVE-2026-5955 | CRITICAL | 9.8 | 0.4% | Jul 9, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software an... |
| CVE-2026-5793 | MEDIUM | 6.1 | 0.3% | Jul 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software an... |
| CVE-2026-56460 | MEDIUM | 6.5 | 0.4% | Jul 9, 2026 | HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API respons... |
| CVE-2026-56459 | MEDIUM | 5.5 | 0.2% | Jul 9, 2026 | HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially s... |
| CVE-2026-56458 | HIGH | 7.5 | 0.2% | Jul 9, 2026 | HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged action... |
| CVE-2026-2342 | CRITICAL | 9.3 | 0.4% | Jul 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Inform... |
| CVE-2026-1989 | HIGH | 7.5 | 0.4% | Jul 9, 2026 | Authorization bypass through User-Controlled key vulnerability in PAVO Financial Technology Solutions Inc. PAVO Pay allo... |
| CVE-2026-1365 | MEDIUM | 6.5 | 0.4% | Jul 9, 2026 | Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentica... |
| CVE-2026-15158 | CRITICAL | 9.8 | 1.0% | Jul 9, 2026 | The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, ... |
| CVE-2026-12433 | MEDIUM | 4.3 | 0.4% | Jul 9, 2026 | The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Obje... |
| CVE-2026-8996 | MEDIUM | 6.5 | 0.3% | Jul 9, 2026 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve... |
| CVE-2026-8848 | HIGH | 7.2 | 0.7% | Jul 9, 2026 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ... |
| CVE-2026-7558 | MEDIUM | 5.3 | 0.3% | Jul 9, 2026 | The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access... |
| CVE-2026-6910 | MEDIUM | 6.4 | 0.2% | Jul 9, 2026 | The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `boo... |
| CVE-2026-59269 | LOW | 3.8 | 0.2% | Jul 9, 2026 | A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in ... |
| CVE-2026-57111 | HIGH | 7.5 | 0.2% | Jul 9, 2026 | Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFi... |
| CVE-2026-4653 | MEDIUM | 6.4 | 0.2% | Jul 9, 2026 | The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin... |
| CVE-2026-33390 | HIGH | 8.1 | 0.2% | Jul 9, 2026 | An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors r... |
| CVE-2026-31985 | HIGH | 8.3 | 0.1% | Jul 9, 2026 | When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disab... |
| CVE-2026-31984 | HIGH | 8.7 | 0.3% | Jul 9, 2026 | A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functional... |
| CVE-2026-31983 | MEDIUM | 6.9 | 0.2% | Jul 9, 2026 | A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attac... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now