2026 CVE Vulnerabilities
61,215 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39574 | CRITICAL | 9.3 | 0.2% | Jun 16, 2026 | Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions. |
| CVE-2026-39490 | HIGH | 7.5 | 0.3% | Jun 16, 2026 | Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions. |
| CVE-2026-39437 | HIGH | 7.1 | 0.1% | Jun 16, 2026 | Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions. |
| CVE-2026-2381 | MEDIUM | 6.5 | 0.3% | Jun 16, 2026 | The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
| CVE-2026-10825 | HIGH | 7.1 | 0.2% | Jun 16, 2026 | A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based ... |
| CVE-2026-8444 | HIGH | 8.8 | 0.3% | Jun 16, 2026 | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpf... |
| CVE-2026-46331 | HIGH | 7.8 | 0.6% | Jun 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page ca... |
| CVE-2026-10093 | MEDIUM | 6.4 | 0.2% | Jun 16, 2026 | The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2026-9187 | MEDIUM | 5.3 | 0.2% | Jun 16, 2026 | The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up t... |
| CVE-2026-8443 | HIGH | 8.8 | 0.3% | Jun 16, 2026 | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameter... |
| CVE-2026-6933 | HIGH | 8.8 | 0.6% | Jun 16, 2026 | The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in version... |
| CVE-2026-5149 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 Thi... |
| CVE-2026-50255 | MEDIUM | 6.7 | 0.1% | Jun 16, 2026 | Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulne... |
| CVE-2026-10780 | MEDIUM | 4.3 | 0.2% | Jun 16, 2026 | The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu... |
| CVE-2026-10635 | MEDIUM | 6.3 | 0.2% | Jun 16, 2026 | On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintain... |
| CVE-2026-6964 | MEDIUM | 5.3 | 0.3% | Jun 16, 2026 | The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i... |
| CVE-2026-7273 | HIGH | 8.8 | 0.3% | Jun 16, 2026 | A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABT... |
| CVE-2026-42014 | MEDIUM | 6.6 | 0.1% | Jun 16, 2026 | A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can ... |
| CVE-2026-1767 | HIGH | 8.1 | 0.2% | Jun 16, 2026 | A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` compo... |
| CVE-2026-1766 | MEDIUM | 6.1 | 0.2% | Jun 16, 2026 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracke... |
| CVE-2026-1765 | MEDIUM | 5.6 | 0.1% | Jun 16, 2026 | A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This ... |
| CVE-2026-1764 | MEDIUM | 5.6 | 0.2% | Jun 16, 2026 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially craf... |
| CVE-2026-12162 | MEDIUM | 5.5 | 0.1% | Jun 16, 2026 | Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an ... |
| CVE-2026-12161 | HIGH | 8.8 | 0.3% | Jun 16, 2026 | Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or mo... |
| CVE-2026-9262 | HIGH | 7.5 | 0.3% | Jun 16, 2026 | Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now