2026 CVE Vulnerabilities
59,953 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12415 | CRITICAL | 9.8 | 0.7% | Jun 27, 2026 | The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on th... |
| CVE-2026-13422 | MEDIUM | 4.3 | 0.2% | Jun 27, 2026 | The HD Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.2.0 to 2.2.1. This is due to ... |
| CVE-2026-13335 | MEDIUM | 6.4 | 0.2% | Jun 27, 2026 | The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point... |
| CVE-2026-13333 | MEDIUM | 6.5 | 0.3% | Jun 27, 2026 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ... |
| CVE-2026-13331 | MEDIUM | 6.5 | 0.3% | Jun 27, 2026 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ... |
| CVE-2026-11356 | MEDIUM | 4.4 | 0.3% | Jun 27, 2026 | The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_t... |
| CVE-2026-56414 | HIGH | 8.6 | 0.4% | Jun 26, 2026 | A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arb... |
| CVE-2026-55975 | HIGH | 8.6 | 0.7% | Jun 26, 2026 | A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to t... |
| CVE-2026-33560 | HIGH | 8.8 | 0.3% | Jun 26, 2026 | The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which a... |
| CVE-2026-31928 | CRITICAL | 9.8 | 0.4% | Jun 26, 2026 | The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are ... |
| CVE-2026-28701 | MEDIUM | 5.3 | 0.8% | Jun 26, 2026 | Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape ... |
| CVE-2026-55069 | HIGH | 8.7 | 0.2% | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAu... |
| CVE-2026-53577 | MEDIUM | 6.5 | 0.3% | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution ... |
| CVE-2026-53576 | CRITICAL | 10 | 0.5% | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for... |
| CVE-2026-50767 | MEDIUM | 5.4 | 0.2% | Jun 26, 2026 | A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System... |
| CVE-2026-50766 | MEDIUM | 5.4 | 0.2% | Jun 26, 2026 | A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 throu... |
| CVE-2026-50765 | MEDIUM | 6.1 | 0.2% | Jun 26, 2026 | A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Man... |
| CVE-2026-49984 | HIGH | 7.7 | 0.4% | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage ba... |
| CVE-2026-49869 | CRITICAL | 10 | 1.0% | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestr... |
| CVE-2026-45807 | HIGH | 7.7 | 0.4% | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints ... |
| CVE-2026-38571 | MEDIUM | 4.6 | 0.2% | Jun 26, 2026 | Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, ... |
| CVE-2026-36908 | MEDIUM | 5.5 | 0.2% | Jun 26, 2026 | A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8... |
| CVE-2026-36907 | MEDIUM | 5.5 | 0.2% | Jun 26, 2026 | A stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-systems Bento4 before v1.8.9allows attackers t... |
| CVE-2026-36478 | HIGH | 7.5 | 0.4% | Jun 26, 2026 | An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsSer... |
| CVE-2026-54353 | HIGH | 7.1 | 0.2% | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypas... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now