2026 CVE Vulnerabilities
59,282 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9626 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the p... |
| CVE-2026-9180 | MEDIUM | 5.3 | 0.3% | Jul 3, 2026 | The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key... |
| CVE-2026-8892 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2026-8489 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2026-14352 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8... |
| CVE-2026-13040 | HIGH | 7.2 | 0.3% | Jul 3, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2026-12557 | MEDIUM | 5.3 | 0.2% | Jul 3, 2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc... |
| CVE-2026-11397 | MEDIUM | 5.5 | 0.2% | Jul 3, 2026 | The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and in... |
| CVE-2026-8921 | HIGH | 8.5 | 0.1% | Jul 3, 2026 | External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary co... |
| CVE-2026-12960 | MEDIUM | 6 | 0.1% | Jul 3, 2026 | An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application o... |
| CVE-2026-14327 | HIGH | 7.5 | 0.5% | Jul 3, 2026 | The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.4... |
| CVE-2026-12920 | MEDIUM | 4.9 | 0.3% | Jul 3, 2026 | The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via ... |
| CVE-2026-12734 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stor... |
| CVE-2026-12731 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stor... |
| CVE-2026-12729 | MEDIUM | 4.3 | 0.2% | Jul 3, 2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Miss... |
| CVE-2026-8247 | HIGH | 8.8 | 0.3% | Jul 3, 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local n... |
| CVE-2026-55726 | MEDIUM | 6.9 | 0.4% | Jul 3, 2026 | The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious us... |
| CVE-2026-54477 | MEDIUM | 5.4 | 0.2% | Jul 3, 2026 | The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks. |
| CVE-2026-13768 | CRITICAL | 10 | 0.6% | Jul 3, 2026 | Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub R... |
| CVE-2026-13728 | MEDIUM | 4.4 | 0.2% | Jul 3, 2026 | In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved... |
| CVE-2026-13722 | HIGH | 7.2 | 0.3% | Jul 3, 2026 | WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore featu... |
| CVE-2026-13384 | HIGH | 7.2 | 0.7% | Jul 3, 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged u... |
| CVE-2026-13383 | HIGH | 7.2 | 0.7% | Jul 3, 2026 | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged ... |
| CVE-2026-13377 | MEDIUM | 4.8 | 0.3% | Jul 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2026-13376 | MEDIUM | 4.8 | 0.3% | Jul 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now