2026 CVE Vulnerabilities
44,056 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14943 | HIGH | 7.5 | 0.1% | Aug 7, 2026 | The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 d... |
| CVE-2026-14331 | MEDIUM | 6.1 | 0.2% | Aug 7, 2026 | The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a... |
| CVE-2026-14205 | CRITICAL | 9.8 | 0.1% | Aug 7, 2026 | The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid... |
| CVE-2026-49005 | LOW | 2.4 | 0.1% | Aug 7, 2026 | The root password hash of the device can be obtained through unencrypted information in the firmware. |
| CVE-2026-19195 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in th... |
| CVE-2026-19193 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys... |
| CVE-2026-19192 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C... |
| CVE-2026-19191 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code o... |
| CVE-2026-14365 | CRITICAL | 9.8 | 0.3% | Aug 7, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in ... |
| CVE-2026-14364 | CRITICAL | 9.8 | 0.3% | Aug 7, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via imp... |
| CVE-2026-12801 | MEDIUM | 6.4 | 0.2% | Aug 7, 2026 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slid... |
| CVE-2026-11907 | MEDIUM | 6.5 | 0.2% | Aug 7, 2026 | The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This ... |
| CVE-2026-19190 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Fil... |
| CVE-2026-49746 | HIGH | 7.1 | 0.1% | Aug 7, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memor... |
| CVE-2026-45204 | MEDIUM | 5.5 | 0.2% | Aug 7, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kern... |
| CVE-2026-45198 | HIGH | 7.8 | 0.2% | Aug 7, 2026 | Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause G... |
| CVE-2026-19189 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functional... |
| CVE-2026-70332 | CRITICAL | 9.6 | 0.4% | Aug 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-68823 | CRITICAL | 9.1 | 0.5% | Aug 7, 2026 | Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a n... |
| CVE-2026-65668 | HIGH | 8.8 | 0.4% | Aug 7, 2026 | Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a netwo... |
| CVE-2026-65667 | CRITICAL | 10 | 0.4% | Aug 7, 2026 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-63508 | CRITICAL | 10 | 0.5% | Aug 7, 2026 | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elev... |
| CVE-2026-62918 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing ... |
| CVE-2026-62896 | CRITICAL | 9.6 | 0.4% | Aug 7, 2026 | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-62873 | CRITICAL | 9.8 | 0.4% | Aug 7, 2026 | Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now