2026 CVE Vulnerabilities
57,111 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11778 | MEDIUM | 5.4 | 0.3% | Jul 3, 2026 | The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbit... |
| CVE-2026-11398 | MEDIUM | 5.3 | 0.3% | Jul 3, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization ... |
| CVE-2026-9230 | MEDIUM | 4.3 | 0.3% | Jul 3, 2026 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass... |
| CVE-2026-9148 | HIGH | 7.2 | 0.3% | Jul 3, 2026 | The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Websi... |
| CVE-2026-8804 | MEDIUM | 6.7 | 0.1% | Jul 3, 2026 | Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensiti... |
| CVE-2026-8351 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Backgrou... |
| CVE-2026-47898 | CRITICAL | 9.8 | 0.1% | Jul 3, 2026 | Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common lib... |
| CVE-2026-47897 | HIGH | 7.5 | 0.4% | Jul 3, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucen... |
| CVE-2026-14544 | CRITICAL | 9.8 | 0.9% | Jul 3, 2026 | A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8... |
| CVE-2026-9547 | HIGH | 7.4 | 0.4% | Jul 3, 2026 | When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION`... |
| CVE-2026-9546 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the document... |
| CVE-2026-9545 | HIGH | 7.5 | 0.3% | Jul 3, 2026 | In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transf... |
| CVE-2026-9080 | HIGH | 7.3 | 0.4% | Jul 3, 2026 | Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerab... |
| CVE-2026-9079 | CRITICAL | 9.8 | 0.8% | Jul 3, 2026 | libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the o... |
| CVE-2026-8932 | HIGH | 7.5 | 0.1% | Jul 3, 2026 | libcurl would reuse a previously created connection even when some mTLS config related option had been changed that shou... |
| CVE-2026-8927 | CRITICAL | 9.1 | 0.3% | Jul 3, 2026 | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails... |
| CVE-2026-8926 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(withou... |
| CVE-2026-8925 | CRITICAL | 9.8 | 0.2% | Jul 3, 2026 | The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing t... |
| CVE-2026-8924 | CRITICAL | 9.1 | 0.2% | Jul 3, 2026 | A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffi... |
| CVE-2026-8458 | MEDIUM | 6.5 | 0.2% | Jul 3, 2026 | libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when ... |
| CVE-2026-8286 | HIGH | 8.1 | 0.4% | Jul 3, 2026 | A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live co... |
| CVE-2026-4967 | HIGH | 7.5 | 0.4% | Jul 3, 2026 | In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of servic... |
| CVE-2026-12064 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs betwe... |
| CVE-2026-11856 | CRITICAL | 9.8 | 0.8% | Jul 3, 2026 | Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then ... |
| CVE-2026-11586 | HIGH | 7.5 | 0.6% | Jul 3, 2026 | By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now