2026 CVE Vulnerabilities
57,068 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9700 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up t... |
| CVE-2026-57895 | HIGH | 8.5 | 0.1% | Jul 8, 2026 | Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executa... |
| CVE-2026-56437 | HIGH | 8.4 | 0.1% | Jul 8, 2026 | Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the... |
| CVE-2026-14500 | MEDIUM | 5.3 | 0.3% | Jul 8, 2026 | The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and i... |
| CVE-2026-14495 | HIGH | 8.8 | 0.4% | Jul 8, 2026 | The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all vers... |
| CVE-2026-14489 | HIGH | 8.8 | 0.6% | Jul 8, 2026 | The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the... |
| CVE-2026-12153 | CRITICAL | 9.8 | 0.4% | Jul 8, 2026 | The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.... |
| CVE-2026-12097 | MEDIUM | 5.3 | 0.3% | Jul 8, 2026 | The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2... |
| CVE-2026-12041 | MEDIUM | 4.4 | 0.2% | Jul 8, 2026 | The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin ... |
| CVE-2026-11798 | MEDIUM | 6.1 | 0.2% | Jul 8, 2026 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Refle... |
| CVE-2026-10570 | MEDIUM | 6.4 | 0.2% | Jul 8, 2026 | The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repea... |
| CVE-2026-9842 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,... |
| CVE-2026-9701 | CRITICAL | 9.8 | 0.3% | Jul 8, 2026 | The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and includ... |
| CVE-2026-14487 | CRITICAL | 9.1 | 0.7% | Jul 8, 2026 | The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val... |
| CVE-2026-14482 | HIGH | 8.8 | 0.3% | Jul 8, 2026 | The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The v... |
| CVE-2026-14244 | HIGH | 7.5 | 0.7% | Jul 8, 2026 | The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu... |
| CVE-2026-14158 | HIGH | 8.8 | 0.5% | Jul 8, 2026 | The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including... |
| CVE-2026-60002 | CRITICAL | 9.4 | 0.3% | Jul 8, 2026 | ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This ... |
| CVE-2026-60001 | MEDIUM | 6.5 | 0.3% | Jul 8, 2026 | sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. |
| CVE-2026-60000 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive au... |
| CVE-2026-59999 | HIGH | 7.5 | 0.1% | Jul 8, 2026 | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not... |
| CVE-2026-59998 | MEDIUM | 6.5 | 0.2% | Jul 8, 2026 | sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if th... |
| CVE-2026-59997 | MEDIUM | 5.4 | 0.2% | Jul 8, 2026 | internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important ... |
| CVE-2026-59996 | MEDIUM | 5.4 | 0.2% | Jul 8, 2026 | scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs betwee... |
| CVE-2026-59995 | MEDIUM | 5.4 | 0.2% | Jul 8, 2026 | sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is u... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now