2026 CVE Vulnerabilities
61,069 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11719 | HIGH | 8.1 | 0.1% | Jun 18, 2026 | An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement... |
| CVE-2026-11718 | CRITICAL | 9.1 | 0.2% | Jun 18, 2026 | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl... |
| CVE-2026-11717 | CRITICAL | 9.1 | 0.2% | Jun 18, 2026 | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl... |
| CVE-2026-8811 | HIGH | 7.1 | 0.3% | Jun 18, 2026 | SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An atta... |
| CVE-2026-8039 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attr... |
| CVE-2026-50643 | MEDIUM | 5.1 | 0.1% | Jun 18, 2026 | 8cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU linemarkers. The compile... |
| CVE-2026-2021 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortc... |
| CVE-2026-9815 | MEDIUM | 6.5 | 0.2% | Jun 18, 2026 | The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenti... |
| CVE-2026-55746 | HIGH | 7.6 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage... |
| CVE-2026-55745 | MEDIUM | 5.4 | 0.1% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ... |
| CVE-2026-55744 | HIGH | 8.6 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ... |
| CVE-2026-55742 | CRITICAL | 9.6 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights ... |
| CVE-2026-55741 | HIGH | 8.8 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configu... |
| CVE-2026-28573 | MEDIUM | 5.5 | 0.1% | Jun 18, 2026 | In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could l... |
| CVE-2026-12137 | MEDIUM | 6.1 | 0.2% | Jun 18, 2026 | The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is... |
| CVE-2026-12136 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysb... |
| CVE-2026-12111 | MEDIUM | 4.3 | 0.3% | Jun 18, 2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to,... |
| CVE-2026-12102 | LOW | 2.7 | 0.3% | Jun 18, 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre... |
| CVE-2026-12098 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed... |
| CVE-2026-11395 | HIGH | 7.2 | 0.2% | Jun 18, 2026 | The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin... |
| CVE-2026-9860 | HIGH | 8.8 | 0.6% | Jun 18, 2026 | The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all ver... |
| CVE-2026-9199 | MEDIUM | 4.3 | 0.2% | Jun 18, 2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl... |
| CVE-2026-55740 | CRITICAL | 9.8 | 0.4% | Jun 18, 2026 | Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthe... |
| CVE-2026-12120 | MEDIUM | 5.3 | 0.3% | Jun 18, 2026 | The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information... |
| CVE-2026-12093 | MEDIUM | 5.3 | 0.4% | Jun 18, 2026 | The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now