2026 CVE Vulnerabilities
61,264 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1291 | MEDIUM | 4.3 | 0.2% | Jun 13, 2026 | The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che... |
| CVE-2026-11624 | CRITICAL | 9.4 | 0.2% | Jun 13, 2026 | The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming conne... |
| CVE-2026-9629 | MEDIUM | 6.4 | 0.2% | Jun 13, 2026 | The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up ... |
| CVE-2026-3297 | MEDIUM | 6.4 | 0.2% | Jun 13, 2026 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2026-2470 | MEDIUM | 4.3 | 0.2% | Jun 13, 2026 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorizatio... |
| CVE-2026-9134 | MEDIUM | 6.4 | 0.2% | Jun 13, 2026 | The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcod... |
| CVE-2026-9109 | HIGH | 7.2 | 0.3% | Jun 13, 2026 | The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vu... |
| CVE-2026-9062 | LOW | 3.4 | 0.2% | Jun 13, 2026 | The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing h... |
| CVE-2026-9061 | LOW | 3.5 | 0.1% | Jun 13, 2026 | The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and o... |
| CVE-2026-11769 | HIGH | 8.8 | 0.4% | Jun 13, 2026 | We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path t... |
| CVE-2026-9848 | HIGH | 7.5 | 0.5% | Jun 13, 2026 | The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in vers... |
| CVE-2026-54231 | MEDIUM | 5.5 | 0.2% | Jun 13, 2026 | A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script... |
| CVE-2026-54230 | HIGH | 7.8 | 0.2% | Jun 13, 2026 | A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts wr... |
| CVE-2026-54229 | HIGH | 7 | 0.1% | Jun 13, 2026 | A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump direc... |
| CVE-2026-54228 | HIGH | 7.8 | 0.1% | Jun 13, 2026 | A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Betwee... |
| CVE-2026-12089 | MEDIUM | 4.9 | 0.3% | Jun 13, 2026 | The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in v... |
| CVE-2026-11443 | MEDIUM | 4.6 | 0.2% | Jun 13, 2026 | Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote at... |
| CVE-2026-11442 | MEDIUM | 6.5 | 1.3% | Jun 13, 2026 | Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attacker... |
| CVE-2026-6676 | HIGH | 7.8 | 0.1% | Jun 12, 2026 | Heap buffer out-of-bounds write vulnerability in Avira Antivirus engine when scanning a malformed POSIX tar archive may ... |
| CVE-2026-12068 | HIGH | 7.4 | 0.3% | Jun 12, 2026 | Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacke... |
| CVE-2026-54398 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions t... |
| CVE-2026-54095 | — | — | — | Jun 12, 2026 | Rejected reason: CVE ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-53826. Reason: This candidate i... |
| CVE-2026-53868 | HIGH | 8.7 | 0.3% | Jun 12, 2026 | Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary... |
| CVE-2026-53867 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remo... |
| CVE-2026-53839 | MEDIUM | 6.5 | 0.3% | Jun 12, 2026 | OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching host... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now