2026 CVE Vulnerabilities
57,056 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31982 | HIGH | 7.1 | 0.2% | Jul 9, 2026 | An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of... |
| CVE-2026-31981 | MEDIUM | 4.8 | 0.1% | Jul 9, 2026 | A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation ... |
| CVE-2026-15000 | HIGH | 7.2 | 0.3% | Jul 9, 2026 | The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp... |
| CVE-2026-14343 | MEDIUM | 6.4 | 0.2% | Jul 9, 2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after... |
| CVE-2026-14342 | MEDIUM | 4.9 | 0.3% | Jul 9, 2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to... |
| CVE-2026-14245 | CRITICAL | 9.8 | 0.6% | Jul 9, 2026 | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass... |
| CVE-2026-13771 | MEDIUM | 6.4 | 0.2% | Jul 9, 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Short... |
| CVE-2026-13450 | MEDIUM | 5.3 | 0.4% | Jul 9, 2026 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ... |
| CVE-2026-13334 | MEDIUM | 6.1 | 0.2% | Jul 9, 2026 | The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all v... |
| CVE-2026-13253 | MEDIUM | 6.4 | 0.2% | Jul 9, 2026 | The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attr... |
| CVE-2026-13080 | MEDIUM | 6.6 | 0.7% | Jul 9, 2026 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Lo... |
| CVE-2026-13011 | MEDIUM | 6.5 | 0.3% | Jul 9, 2026 | The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulner... |
| CVE-2026-12418 | MEDIUM | 5.3 | 0.2% | Jul 9, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-12406 | MEDIUM | 5.3 | 0.3% | Jul 9, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-12170 | MEDIUM | 6.4 | 0.3% | Jul 9, 2026 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v... |
| CVE-2026-11359 | MEDIUM | 4.3 | 0.2% | Jul 9, 2026 | The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerab... |
| CVE-2026-47840 | CRITICAL | 9.3 | 0.1% | Jul 9, 2026 | A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate fro... |
| CVE-2026-47831 | HIGH | 7.7 | 0.2% | Jul 9, 2026 | Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-... |
| CVE-2026-47830 | HIGH | 8.8 | 0.1% | Jul 9, 2026 | Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege ... |
| CVE-2026-47829 | HIGH | 7.8 | 0.3% | Jul 9, 2026 | Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-s... |
| CVE-2026-47828 | HIGH | 8.8 | 0.1% | Jul 9, 2026 | During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new ... |
| CVE-2026-47826 | CRITICAL | 9.1 | 0.3% | Jul 9, 2026 | The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfi... |
| CVE-2026-12517 | MEDIUM | 5.3 | 0.1% | Jul 9, 2026 | The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performe... |
| CVE-2026-12516 | MEDIUM | 5.3 | 0.1% | Jul 9, 2026 | The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performe... |
| CVE-2026-12270 | MEDIUM | 6.5 | 0.1% | Jul 9, 2026 | The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belong... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now