2026 CVE Vulnerabilities
44,054 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49006 | MEDIUM | 5.3 | 0.1% | Aug 7, 2026 | By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmiss... |
| CVE-2026-19079 | MEDIUM | 4.4 | 0.1% | Aug 7, 2026 | A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. W... |
| CVE-2026-16027 | MEDIUM | 5.4 | 0.2% | Aug 7, 2026 | Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Requ... |
| CVE-2026-15239 | MEDIUM | 5.3 | 0.1% | Aug 7, 2026 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache... |
| CVE-2026-15211 | MEDIUM | 5.9 | 0.1% | Aug 7, 2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal ... |
| CVE-2026-15148 | MEDIUM | 5.3 | 0.1% | Aug 7, 2026 | The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates fro... |
| CVE-2026-12261 | MEDIUM | 5.3 | 0.2% | Aug 7, 2026 | A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisonin... |
| CVE-2026-19196 | HIGH | 7.3 | 0.3% | Aug 7, 2026 | A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the ... |
| CVE-2026-16265 | MEDIUM | 6.5 | 0.1% | Aug 7, 2026 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not r... |
| CVE-2026-16263 | HIGH | 8.8 | 0.3% | Aug 7, 2026 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not p... |
| CVE-2026-16262 | HIGH | 7.5 | 0.1% | Aug 7, 2026 | The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating... |
| CVE-2026-16258 | CRITICAL | 9.8 | 0.2% | Aug 7, 2026 | The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing u... |
| CVE-2026-16041 | HIGH | 7.5 | 0.1% | Aug 7, 2026 | The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST p... |
| CVE-2026-16039 | MEDIUM | 6.5 | 0.1% | Aug 7, 2026 | The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, ... |
| CVE-2026-16038 | CRITICAL | 9.1 | 0.1% | Aug 7, 2026 | The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an or... |
| CVE-2026-16030 | HIGH | 8.1 | 0.1% | Aug 7, 2026 | The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used t... |
| CVE-2026-15386 | MEDIUM | 5.4 | 0.2% | Aug 7, 2026 | The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an att... |
| CVE-2026-15361 | HIGH | 8.1 | 0.2% | Aug 7, 2026 | The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does n... |
| CVE-2026-15359 | MEDIUM | 6.5 | 0.1% | Aug 7, 2026 | The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allow... |
| CVE-2026-15245 | MEDIUM | 5.4 | 0.2% | Aug 7, 2026 | The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript con... |
| CVE-2026-15215 | HIGH | 8.8 | 0.2% | Aug 7, 2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing ... |
| CVE-2026-15214 | MEDIUM | 4.3 | 0.1% | Aug 7, 2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription... |
| CVE-2026-15032 | MEDIUM | 6.1 | 0.2% | Aug 7, 2026 | The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an... |
| CVE-2026-14943 | HIGH | 7.5 | 0.1% | Aug 7, 2026 | The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 d... |
| CVE-2026-14331 | MEDIUM | 6.1 | 0.2% | Aug 7, 2026 | The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now