2026 CVE Vulnerabilities
57,114 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12064 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs betwe... |
| CVE-2026-11856 | CRITICAL | 9.8 | 0.8% | Jul 3, 2026 | Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then ... |
| CVE-2026-11586 | HIGH | 7.5 | 0.6% | Jul 3, 2026 | By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation... |
| CVE-2026-11564 | CRITICAL | 9.1 | 0.5% | Jul 3, 2026 | libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches ... |
| CVE-2026-11352 | HIGH | 7.5 | 0.8% | Jul 3, 2026 | An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service agai... |
| CVE-2026-10536 | CRITICAL | 9.8 | 0.6% | Jul 3, 2026 | A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CU... |
| CVE-2026-9725 | CRITICAL | 9.1 | 0.7% | Jul 3, 2026 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletio... |
| CVE-2026-9626 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the p... |
| CVE-2026-9180 | MEDIUM | 5.3 | 0.3% | Jul 3, 2026 | The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key... |
| CVE-2026-8892 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2026-8489 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2026-14352 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8... |
| CVE-2026-13040 | HIGH | 7.2 | 0.3% | Jul 3, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2026-12557 | MEDIUM | 5.3 | 0.2% | Jul 3, 2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc... |
| CVE-2026-11397 | MEDIUM | 5.5 | 0.2% | Jul 3, 2026 | The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and in... |
| CVE-2026-8921 | HIGH | 8.5 | 0.1% | Jul 3, 2026 | External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary co... |
| CVE-2026-12960 | MEDIUM | 6 | 0.1% | Jul 3, 2026 | An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application o... |
| CVE-2026-14327 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.4... |
| CVE-2026-12920 | MEDIUM | 4.9 | 0.3% | Jul 3, 2026 | The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via ... |
| CVE-2026-12734 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stor... |
| CVE-2026-12731 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stor... |
| CVE-2026-12729 | MEDIUM | 4.3 | 0.2% | Jul 3, 2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Miss... |
| CVE-2026-8247 | HIGH | 8.8 | 0.3% | Jul 3, 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local n... |
| CVE-2026-55726 | MEDIUM | 6.9 | 0.4% | Jul 3, 2026 | The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious us... |
| CVE-2026-54477 | MEDIUM | 5.4 | 0.2% | Jul 3, 2026 | The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now