2026 CVE Vulnerabilities
43,564 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14185 | MEDIUM | 4.3 | 0.1% | Jul 21, 2026 | The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-... |
| CVE-2026-14184 | MEDIUM | 5.4 | 0.1% | Jul 21, 2026 | The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of... |
| CVE-2026-14183 | MEDIUM | 4.3 | 0.1% | Jul 21, 2026 | The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt han... |
| CVE-2026-13694 | MEDIUM | 6.5 | 0.1% | Jul 21, 2026 | The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated tr... |
| CVE-2026-13693 | MEDIUM | 5.9 | 0.2% | Jul 21, 2026 | The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the ... |
| CVE-2026-3182 | MEDIUM | 4.3 | 0.3% | Jul 21, 2026 | Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive ... |
| CVE-2026-16266 | MEDIUM | 6.3 | 0.2% | Jul 21, 2026 | Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in ... |
| CVE-2026-15927 | MEDIUM | 6.8 | 0.3% | Jul 21, 2026 | A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints... |
| CVE-2026-15812 | MEDIUM | 4.8 | 0.2% | Jul 21, 2026 | A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). ... |
| CVE-2026-15811 | MEDIUM | 5.8 | 0.1% | Jul 21, 2026 | A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not... |
| CVE-2026-15782 | MEDIUM | 4.9 | 0.2% | Jul 21, 2026 | The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPres... |
| CVE-2026-15156 | MEDIUM | 6.4 | 0.2% | Jul 21, 2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ... |
| CVE-2026-16336 | MEDIUM | 5.3 | 0.3% | Jul 21, 2026 | A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/jav... |
| CVE-2026-63729 | MEDIUM | 6.8 | 0.1% | Jul 21, 2026 | The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince co... |
| CVE-2026-16334 | MEDIUM | 6.3 | 0.2% | Jul 21, 2026 | A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code o... |
| CVE-2026-64626 | MEDIUM | 6.4 | 0.2% | Jul 20, 2026 | AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the en... |
| CVE-2026-57852 | MEDIUM | 6.3 | 0.4% | Jul 20, 2026 | Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote att... |
| CVE-2026-51385 | MEDIUM | 6.9 | 0.4% | Jul 20, 2026 | An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code v... |
| CVE-2026-51025 | MEDIUM | 6.1 | 0.2% | Jul 20, 2026 | Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary... |
| CVE-2026-47144 | MEDIUM | 5.5 | 0.1% | Jul 20, 2026 | Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame... |
| CVE-2026-47134 | MEDIUM | 6.9 | 0.1% | Jul 20, 2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private k... |
| CVE-2026-47133 | MEDIUM | 6.9 | 0.1% | Jul 20, 2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5.... |
| CVE-2026-47128 | MEDIUM | 6.1 | 0.1% | Jul 20, 2026 | nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landloc... |
| CVE-2026-12900 | MEDIUM | 6.4 | 0.2% | Jul 20, 2026 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2026-64651 | MEDIUM | 6.3 | 0.1% | Jul 20, 2026 | The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed bridge. Prior to version 1.0.2... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now