2026 CVE Vulnerabilities
43,896 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19266 | MEDIUM | 5.5 | 1.5% | Aug 8, 2026 | A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the f... |
| CVE-2026-19263 | HIGH | 7.3 | 1.3% | Aug 8, 2026 | A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted elem... |
| CVE-2026-19259 | MEDIUM | 5.3 | 0.1% | Aug 8, 2026 | A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping... |
| CVE-2026-16955 | MEDIUM | 5 | 0.2% | Aug 8, 2026 | The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwardi... |
| CVE-2026-16953 | MEDIUM | 4.8 | 0.1% | Aug 8, 2026 | The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deleti... |
| CVE-2026-16948 | HIGH | 8.1 | 0.1% | Aug 8, 2026 | The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exp... |
| CVE-2026-16608 | MEDIUM | 5.3 | 0.1% | Aug 8, 2026 | The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging ... |
| CVE-2026-16595 | MEDIUM | 6.5 | 0.1% | Aug 8, 2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti... |
| CVE-2026-16594 | HIGH | 7.5 | 0.1% | Aug 8, 2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti... |
| CVE-2026-16590 | MEDIUM | 6.5 | 0.1% | Aug 8, 2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti... |
| CVE-2026-16589 | HIGH | 7.7 | 0.2% | Aug 8, 2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL sta... |
| CVE-2026-16578 | HIGH | 7.5 | 0.2% | Aug 8, 2026 | The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does n... |
| CVE-2026-16574 | MEDIUM | 5.4 | 0.1% | Aug 8, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that ... |
| CVE-2026-16562 | MEDIUM | 6.5 | 0.1% | Aug 8, 2026 | The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics ... |
| CVE-2026-16559 | MEDIUM | 6.8 | 0.2% | Aug 8, 2026 | The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload featur... |
| CVE-2026-16558 | MEDIUM | 5.4 | 0.2% | Aug 8, 2026 | The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it... |
| CVE-2026-16535 | MEDIUM | 6.1 | 0.2% | Aug 8, 2026 | The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a r... |
| CVE-2026-16282 | MEDIUM | 5.3 | 0.1% | Aug 8, 2026 | The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against t... |
| CVE-2026-16269 | MEDIUM | 4.8 | 0.2% | Aug 8, 2026 | The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthentica... |
| CVE-2026-16267 | HIGH | 8.1 | 0.2% | Aug 8, 2026 | The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from... |
| CVE-2026-14526 | CRITICAL | 9.8 | 0.6% | Aug 8, 2026 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and... |
| CVE-2026-18988 | MEDIUM | 6.4 | 0.3% | Aug 8, 2026 | The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block a... |
| CVE-2026-13505 | HIGH | 8.7 | 0.3% | Aug 8, 2026 | In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X ser... |
| CVE-2026-8798 | HIGH | 8.7 | 0.3% | Aug 8, 2026 | In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried ... |
| CVE-2026-52880 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now