2026 CVE Vulnerabilities
60,149 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57234 | LOW | 2.6 | 0.2% | Jun 25, 2026 | Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse opti... |
| CVE-2026-49319 | MEDIUM | 6.9 | 0.2% | Jun 25, 2026 | Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., L... |
| CVE-2026-46735 | HIGH | 7.8 | 0.7% | Jun 25, 2026 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Ele... |
| CVE-2026-13314 | LOW | 2 | 0.3% | Jun 25, 2026 | Malicious HTML content could be injected into the content rendered by the pretix-digital plugin. |
| CVE-2026-13225 | MEDIUM | 5.3 | 0.3% | Jun 25, 2026 | Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization o... |
| CVE-2026-13223 | MEDIUM | 6.3 | 0.3% | Jun 25, 2026 | Our payment integration with Computop-based payment methods did not properly validate payment status responses. An atta... |
| CVE-2026-13222 | MEDIUM | 6.3 | 0.3% | Jun 25, 2026 | Our payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacke... |
| CVE-2026-57619 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions. |
| CVE-2026-57429 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Contributor Broken Access Control in Slim SEO <= 4.6.2 versions. |
| CVE-2026-56122 | HIGH | 8.7 | 0.4% | Jun 25, 2026 | Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to ... |
| CVE-2026-56071 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions. |
| CVE-2026-56054 | HIGH | 7.7 | 0.4% | Jun 25, 2026 | Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions. |
| CVE-2026-56053 | HIGH | 8.8 | 0.4% | Jun 25, 2026 | Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions. |
| CVE-2026-56051 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions. |
| CVE-2026-56050 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access ... |
| CVE-2026-56049 | HIGH | 8.5 | 0.4% | Jun 25, 2026 | Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions. |
| CVE-2026-56042 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions. |
| CVE-2026-56023 | MEDIUM | 5.4 | 0.2% | Jun 25, 2026 | Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions. |
| CVE-2026-56014 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions. |
| CVE-2026-56013 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions. |
| CVE-2026-56006 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions. |
| CVE-2026-56005 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions. |
| CVE-2026-54849 | CRITICAL | 9.3 | 0.2% | Jun 25, 2026 | Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions. |
| CVE-2026-54848 | HIGH | 8.3 | 0.2% | Jun 25, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows R... |
| CVE-2026-54845 | HIGH | 8.1 | 0.3% | Jun 25, 2026 | Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now