2026 CVE Vulnerabilities
60,243 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7547 | MEDIUM | 4.9 | 0.4% | Jun 19, 2026 | The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in ... |
| CVE-2026-7515 | CRITICAL | 9.8 | 0.9% | Jun 19, 2026 | The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 vi... |
| CVE-2026-56132 | MEDIUM | 6.9 | 0.1% | Jun 19, 2026 | In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array... |
| CVE-2026-56131 | MEDIUM | 4.9 | 0.1% | Jun 19, 2026 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a... |
| CVE-2026-54414 | CRITICAL | 9.8 | 1.1% | Jun 19, 2026 | FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedF... |
| CVE-2026-4328 | MEDIUM | 6.4 | 0.2% | Jun 19, 2026 | The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includi... |
| CVE-2026-1856 | MEDIUM | 6.4 | 0.2% | Jun 19, 2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking fi... |
| CVE-2026-12644 | MEDIUM | 5.5 | 0.3% | Jun 19, 2026 | Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of b... |
| CVE-2026-12430 | MEDIUM | 4.4 | 0.2% | Jun 19, 2026 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio... |
| CVE-2026-12157 | MEDIUM | 6.4 | 0.2% | Jun 19, 2026 | The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to S... |
| CVE-2026-11989 | MEDIUM | 6.5 | 0.3% | Jun 19, 2026 | The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vuln... |
| CVE-2026-11752 | MEDIUM | 5.9 | 0.2% | Jun 19, 2026 | A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS mod... |
| CVE-2026-10779 | MEDIUM | 4.3 | 0.2% | Jun 19, 2026 | The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization... |
| CVE-2026-10720 | MEDIUM | 5.1 | 0.2% | Jun 19, 2026 | Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-im... |
| CVE-2026-10034 | MEDIUM | 5.3 | 0.4% | Jun 19, 2026 | The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin... |
| CVE-2026-8806 | HIGH | 8.7 | 0.4% | Jun 19, 2026 | Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET... |
| CVE-2026-8805 | HIGH | 8.7 | 0.4% | Jun 19, 2026 | Integer Overflow or Wraparound vulnerability in the EtherNet/IP function of Mitsubishi Electric MELSEC iQ-F Series FX5-E... |
| CVE-2026-11775 | MEDIUM | 4.3 | 0.1% | Jun 19, 2026 | The User Admin Simplifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2026-52866 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing l... |
| CVE-2026-50034 | HIGH | 7.1 | 0.1% | Jun 19, 2026 | An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related... |
| CVE-2026-40624 | CRITICAL | 9.8 | 0.6% | Jun 19, 2026 | Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated att... |
| CVE-2026-12050 | HIGH | 8.8 | 0.2% | Jun 19, 2026 | SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-sup... |
| CVE-2026-12049 | MEDIUM | 6.1 | 0.3% | Jun 19, 2026 | Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user... |
| CVE-2026-12048 | MEDIUM | 5.4 | 0.3% | Jun 19, 2026 | Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL ... |
| CVE-2026-12047 | MEDIUM | 5.4 | 0.2% | Jun 19, 2026 | HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now