2026 CVE Vulnerabilities
43,891 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18465 | MEDIUM | 6.5 | 0.3% | Aug 9, 2026 | The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a... |
| CVE-2026-18464 | HIGH | 7.5 | 0.1% | Aug 9, 2026 | The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a... |
| CVE-2026-18357 | HIGH | 7.5 | 0.1% | Aug 9, 2026 | The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of... |
| CVE-2026-18037 | MEDIUM | 6.5 | 0.1% | Aug 9, 2026 | The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of it... |
| CVE-2026-18032 | HIGH | 7.5 | 0.1% | Aug 9, 2026 | The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthent... |
| CVE-2026-17044 | HIGH | 8.6 | 0.2% | Aug 9, 2026 | The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it ... |
| CVE-2026-17017 | HIGH | 8.1 | 0.2% | Aug 9, 2026 | The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in... |
| CVE-2026-17014 | MEDIUM | 5.3 | 0.1% | Aug 9, 2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its ... |
| CVE-2026-17011 | LOW | 3.8 | 0.1% | Aug 9, 2026 | The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpo... |
| CVE-2026-16992 | MEDIUM | 6.5 | 0.1% | Aug 9, 2026 | The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of it... |
| CVE-2026-16988 | HIGH | 7.5 | 0.1% | Aug 9, 2026 | The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker dat... |
| CVE-2026-16965 | MEDIUM | 4.3 | 0.1% | Aug 9, 2026 | The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, a... |
| CVE-2026-16957 | LOW | 2.7 | 0.1% | Aug 9, 2026 | The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed ... |
| CVE-2026-16032 | MEDIUM | 6.1 | 0.2% | Aug 9, 2026 | The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated an... |
| CVE-2026-15038 | CRITICAL | 9.8 | 0.2% | Aug 9, 2026 | The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenti... |
| CVE-2026-19334 | MEDIUM | 5.3 | 0.6% | Aug 9, 2026 | A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown pa... |
| CVE-2026-19333 | MEDIUM | 5.3 | 0.6% | Aug 9, 2026 | A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a... |
| CVE-2026-19332 | MEDIUM | 5.3 | 0.6% | Aug 9, 2026 | A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functi... |
| CVE-2026-19331 | MEDIUM | 5.3 | 0.1% | Aug 9, 2026 | A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanva... |
| CVE-2026-19330 | MEDIUM | 5.3 | 0.1% | Aug 9, 2026 | A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_s... |
| CVE-2026-19329 | MEDIUM | 5.3 | 0.6% | Aug 9, 2026 | A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element i... |
| CVE-2026-10595 | HIGH | 7.5 | 0.5% | Aug 9, 2026 | A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemen... |
| CVE-2026-19328 | MEDIUM | 5.3 | 0.1% | Aug 9, 2026 | A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/insta... |
| CVE-2026-19327 | MEDIUM | 5.3 | 0.1% | Aug 9, 2026 | A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession ... |
| CVE-2026-19326 | MEDIUM | 4.4 | 0.1% | Aug 9, 2026 | A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now