2026 CVE Vulnerabilities
43,380 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9713 | HIGH | 7.5 | 0.5% | Jul 23, 2026 | The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table'... |
| CVE-2026-59678 | HIGH | 7.1 | 0.2% | Jul 23, 2026 | An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary fi... |
| CVE-2026-12421 | HIGH | 7.2 | 0.3% | Jul 23, 2026 | The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all version... |
| CVE-2026-14291 | HIGH | 7.5 | 0.3% | Jul 23, 2026 | The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its ... |
| CVE-2026-12082 | HIGH | 7.5 | 0.2% | Jul 23, 2026 | The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes... |
| CVE-2026-7534 | HIGH | 7.2 | 0.3% | Jul 23, 2026 | The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST AP... |
| CVE-2026-7232 | HIGH | 7.2 | 0.3% | Jul 23, 2026 | The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in ... |
| CVE-2026-64600 | HIGH | 7.8 | 0.5% | Jul 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling I... |
| CVE-2026-15074 | HIGH | 7.5 | 0.5% | Jul 23, 2026 | @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the... |
| CVE-2026-16632 | HIGH | 7.3 | 0.5% | Jul 23, 2026 | A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the lib... |
| CVE-2026-61246 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60455 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60439 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60373 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60371 | HIGH | 8 | 0.1% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60370 | HIGH | 7.5 | 0.2% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-60368 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third... |
| CVE-2026-38766 | HIGH | 7.8 | 0.2% | Jul 22, 2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_1... |
| CVE-2026-38765 | HIGH | 7.8 | 0.2% | Jul 22, 2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne... |
| CVE-2026-64797 | HIGH | 7.5 | 0.1% | Jul 22, 2026 | Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client... |
| CVE-2026-64792 | HIGH | 7.5 | 0.1% | Jul 22, 2026 | Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extension... |
| CVE-2026-64791 | HIGH | 8.8 | 0.1% | Jul 22, 2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager... |
| CVE-2026-63685 | HIGH | 8.8 | 0.1% | Jul 22, 2026 | Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacemen... |
| CVE-2026-63684 | HIGH | 8.8 | 0.1% | Jul 22, 2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export ac... |
| CVE-2026-63683 | HIGH | 7.5 | 0.1% | Jul 22, 2026 | Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now