2026 CVE Vulnerabilities
43,635 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44251 | MEDIUM | 6.5 | 0.3% | Jul 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and abov... |
| CVE-2026-2594 | MEDIUM | 6.4 | 0.2% | Jul 17, 2026 | The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi... |
| CVE-2026-33754 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and abov... |
| CVE-2026-44452 | MEDIUM | 5.9 | 0.3% | Jul 16, 2026 | h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientH... |
| CVE-2026-44434 | MEDIUM | 5.3 | 0.1% | Jul 16, 2026 | Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dc... |
| CVE-2026-62826 | MEDIUM | 5.4 | 0.2% | Jul 16, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-58643 | MEDIUM | 6.1 | 0.2% | Jul 16, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an u... |
| CVE-2026-45334 | MEDIUM | 5.3 | 0.4% | Jul 16, 2026 | Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature ret... |
| CVE-2026-44176 | MEDIUM | 6 | 0.2% | Jul 16, 2026 | Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` per... |
| CVE-2026-14782 | MEDIUM | 4.9 | 0.2% | Jul 16, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Cu... |
| CVE-2026-13713 | MEDIUM | 6.2 | 0.2% | Jul 16, 2026 | YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on ... |
| CVE-2026-61378 | MEDIUM | 6.8 | 0.1% | Jul 16, 2026 | A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to... |
| CVE-2026-60073 | MEDIUM | 5.9 | 0.2% | Jul 16, 2026 | An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB ... |
| CVE-2026-57896 | MEDIUM | 6.9 | 0.1% | Jul 16, 2026 | An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti... |
| CVE-2026-36425 | MEDIUM | 6.5 | 0.3% | Jul 16, 2026 | An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user... |
| CVE-2026-33731 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/Aut... |
| CVE-2026-62299 | MEDIUM | 5.3 | 0.3% | Jul 16, 2026 | CoreDNS is a DNS server written in Go. Prior to 1.14.5, the CoreDNS rewrite plugin supports edns0 rewrite rules with an ... |
| CVE-2026-61718 | MEDIUM | 5.4 | 0.3% | Jul 16, 2026 | bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb w... |
| CVE-2026-60140 | MEDIUM | 6.9 | 0.1% | Jul 16, 2026 | An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupti... |
| CVE-2026-54728 | MEDIUM | 6.1 | 0.2% | Jul 16, 2026 | bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb ... |
| CVE-2026-15449 | MEDIUM | 5.8 | 0.1% | Jul 16, 2026 | A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC... |
| CVE-2026-53536 | MEDIUM | 5.3 | 0.2% | Jul 16, 2026 | Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endp... |
| CVE-2026-53535 | MEDIUM | 5.9 | 0.6% | Jul 16, 2026 | Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-conf... |
| CVE-2026-47089 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin acces... |
| CVE-2026-47085 | MEDIUM | 4 | 0.2% | Jul 16, 2026 | An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxk... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now