2026 CVE Vulnerabilities
43,657 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12391 | MEDIUM | 5 | — | Jul 16, 2026 | An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) with... |
| CVE-2026-59249 | MEDIUM | 6.3 | — | Jul 16, 2026 | Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malici... |
| CVE-2026-35148 | MEDIUM | 6.3 | 0.2% | Jul 16, 2026 | HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints ar... |
| CVE-2026-35146 | MEDIUM | 6.3 | 0.1% | Jul 16, 2026 | HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish conn... |
| CVE-2026-6424 | MEDIUM | 6.7 | 0.1% | Jul 16, 2026 | Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the syste... |
| CVE-2026-15727 | MEDIUM | 4.9 | — | Jul 16, 2026 | The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in ... |
| CVE-2026-15651 | MEDIUM | 4.9 | 0.3% | Jul 16, 2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' para... |
| CVE-2026-15610 | MEDIUM | 4.3 | — | Jul 16, 2026 | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio... |
| CVE-2026-15407 | MEDIUM | 4.3 | 0.3% | Jul 16, 2026 | The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7... |
| CVE-2026-15350 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.... |
| CVE-2026-15324 | MEDIUM | 4.4 | 0.2% | Jul 16, 2026 | The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to St... |
| CVE-2026-15106 | MEDIUM | 5.3 | — | Jul 16, 2026 | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorizatio... |
| CVE-2026-15099 | MEDIUM | 6.4 | — | Jul 16, 2026 | The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute ... |
| CVE-2026-15022 | MEDIUM | 6.5 | 0.3% | Jul 16, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Sto... |
| CVE-2026-15021 | MEDIUM | 6.4 | 0.2% | Jul 16, 2026 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all v... |
| CVE-2026-13767 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, an... |
| CVE-2026-13755 | MEDIUM | 6.4 | — | Jul 16, 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_... |
| CVE-2026-13754 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' param... |
| CVE-2026-12979 | MEDIUM | 5.5 | — | Jul 16, 2026 | The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a t... |
| CVE-2026-12869 | MEDIUM | 6.1 | — | Jul 16, 2026 | The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for ... |
| CVE-2026-12684 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or non... |
| CVE-2026-12510 | MEDIUM | 5.9 | 0.1% | Jul 16, 2026 | The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a c... |
| CVE-2026-12395 | MEDIUM | 6.5 | 0.2% | Jul 16, 2026 | The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a ... |
| CVE-2026-11866 | MEDIUM | 5.4 | 0.1% | Jul 16, 2026 | The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing a... |
| CVE-2026-11371 | MEDIUM | 6.1 | — | Jul 16, 2026 | The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now