2026 CVE Vulnerabilities
57,068 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5356 | HIGH | 7.5 | — | Jul 8, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input... |
| CVE-2026-14454 | CRITICAL | 9.8 | 0.4% | Jul 8, 2026 | Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD ... |
| CVE-2026-12002 | MEDIUM | 4.7 | — | Jul 8, 2026 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request ... |
| CVE-2026-6854 | HIGH | 7.5 | — | Jul 8, 2026 | The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the ... |
| CVE-2026-6818 | HIGH | 7.2 | — | Jul 8, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spe... |
| CVE-2026-6742 | MEDIUM | 6.4 | — | Jul 8, 2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in ... |
| CVE-2026-6371 | MEDIUM | 4.8 | 0.1% | Jul 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Limatek System Inc... |
| CVE-2026-6230 | HIGH | 7.5 | — | Jul 8, 2026 | The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all ve... |
| CVE-2026-41042 | CRITICAL | 9.1 | — | Jul 8, 2026 | Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java... |
| CVE-2026-3688 | HIGH | 8.1 | — | Jul 8, 2026 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure... |
| CVE-2026-14250 | MEDIUM | 6.3 | — | Jul 8, 2026 | The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu... |
| CVE-2026-12936 | MEDIUM | 4.9 | — | Jul 8, 2026 | The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ... |
| CVE-2026-15041 | LOW | 3.7 | 0.3% | Jul 8, 2026 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for co... |
| CVE-2026-56003 | HIGH | 8.8 | 0.6% | Jul 8, 2026 | A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeSc... |
| CVE-2026-56002 | HIGH | 8.8 | 0.5% | Jul 8, 2026 | A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers auth... |
| CVE-2026-6280 | MEDIUM | 6.5 | 0.2% | Jul 8, 2026 | Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consu... |
| CVE-2026-57260 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly re... |
| CVE-2026-57259 | MEDIUM | 6.5 | 0.2% | Jul 8, 2026 | The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, th... |
| CVE-2026-57258 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underl... |
| CVE-2026-57257 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-o... |
| CVE-2026-57256 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and thi... |
| CVE-2026-57255 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malfo... |
| CVE-2026-57254 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF,... |
| CVE-2026-57253 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an in... |
| CVE-2026-57252 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotatio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now