2026 CVE Vulnerabilities
60,251 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12098 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed... |
| CVE-2026-11395 | HIGH | 7.2 | 0.2% | Jun 18, 2026 | The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin... |
| CVE-2026-9860 | HIGH | 8.8 | 0.6% | Jun 18, 2026 | The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all ver... |
| CVE-2026-9199 | MEDIUM | 4.3 | 0.2% | Jun 18, 2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl... |
| CVE-2026-55740 | CRITICAL | 9.8 | 0.4% | Jun 18, 2026 | Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthe... |
| CVE-2026-12120 | MEDIUM | 5.3 | 0.3% | Jun 18, 2026 | The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information... |
| CVE-2026-12093 | MEDIUM | 5.3 | 0.4% | Jun 18, 2026 | The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4... |
| CVE-2026-11784 | MEDIUM | 4.3 | 0.2% | Jun 18, 2026 | The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vuln... |
| CVE-2026-11777 | MEDIUM | 4.9 | 0.4% | Jun 18, 2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic... |
| CVE-2026-11776 | MEDIUM | 4.9 | 0.4% | Jun 18, 2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic... |
| CVE-2026-11402 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The Services Section Block – Showcase Service Details in Grid or Columns plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2026-11360 | MEDIUM | 4.9 | 0.4% | Jun 18, 2026 | The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_dire... |
| CVE-2026-11358 | MEDIUM | 4.4 | 0.2% | Jun 18, 2026 | The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress is vulne... |
| CVE-2026-11357 | MEDIUM | 4.3 | 0.2% | Jun 18, 2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Informati... |
| CVE-2026-10736 | MEDIUM | 4.9 | 0.4% | Jun 18, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the... |
| CVE-2026-10623 | MEDIUM | 4.3 | 0.3% | Jun 18, 2026 | The PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin plugin for WordPress is vulnerable to Insecur... |
| CVE-2026-10029 | MEDIUM | 5.3 | 0.3% | Jun 18, 2026 | The Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitiv... |
| CVE-2026-12505 | HIGH | 7.8 | 0.2% | Jun 18, 2026 | A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges befor... |
| CVE-2026-12407 | HIGH | 8.8 | 0.4% | Jun 18, 2026 | The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to,... |
| CVE-2026-10023 | MEDIUM | 4.3 | 0.3% | Jun 18, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPr... |
| CVE-2026-12569 | CRITICAL | 9.8 | 2.3% | Jun 18, 2026 | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vul... |
| CVE-2026-48768 | CRITICAL | 9.3 | 0.3% | Jun 18, 2026 | TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is... |
| CVE-2026-48764 | HIGH | 8.2 | 0.3% | Jun 18, 2026 | TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname o... |
| CVE-2026-54533 | MEDIUM | 6.9 | 0.3% | Jun 17, 2026 | vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms ... |
| CVE-2026-54445 | MEDIUM | 6.9 | 0.3% | Jun 17, 2026 | vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial us... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now