2026 CVE Vulnerabilities
43,896 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15540 | MEDIUM | 4.3 | 0.2% | Jul 13, 2026 | A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function... |
| CVE-2026-15539 | MEDIUM | 4.7 | 0.2% | Jul 13, 2026 | A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown functi... |
| CVE-2026-15538 | MEDIUM | 6.3 | 0.3% | Jul 13, 2026 | A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutate... |
| CVE-2026-15536 | MEDIUM | 6.3 | 0.2% | Jul 13, 2026 | A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file ... |
| CVE-2026-12397 | MEDIUM | 4.3 | 0.1% | Jul 13, 2026 | The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email fo... |
| CVE-2026-12396 | MEDIUM | 5.4 | 0.1% | Jul 13, 2026 | The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job mod... |
| CVE-2026-12274 | MEDIUM | 6.5 | 0.1% | Jul 13, 2026 | The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post ... |
| CVE-2026-12273 | MEDIUM | 4.3 | 0.1% | Jul 13, 2026 | The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creati... |
| CVE-2026-12271 | MEDIUM | 5.4 | 0.1% | Jul 13, 2026 | The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to i... |
| CVE-2026-12081 | MEDIUM | 5 | 0.2% | Jul 13, 2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classe... |
| CVE-2026-10551 | MEDIUM | 6.1 | 0.2% | Jul 13, 2026 | The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to... |
| CVE-2026-15535 | MEDIUM | 6.3 | 0.2% | Jul 13, 2026 | A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this is... |
| CVE-2026-15533 | MEDIUM | 4.7 | 0.2% | Jul 13, 2026 | A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of ... |
| CVE-2026-15531 | MEDIUM | 5.3 | 0.1% | Jul 13, 2026 | A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected ... |
| CVE-2026-15530 | MEDIUM | 5.5 | 0.3% | Jul 13, 2026 | A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the fi... |
| CVE-2026-15553 | MEDIUM | 6.9 | 0.3% | Jul 13, 2026 | Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote ... |
| CVE-2026-15552 | MEDIUM | 6.1 | 0.2% | Jul 13, 2026 | Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowing unauthenticated r... |
| CVE-2026-15529 | MEDIUM | 6.3 | 0.3% | Jul 13, 2026 | A vulnerability was detected in yzhao062 pyod up to 3.6.1. Affected is the function pyod.utils.persistence.load of the f... |
| CVE-2026-15527 | MEDIUM | 5.3 | 0.1% | Jul 13, 2026 | A vulnerability has been found in better-auth better-icons up to 1.0.5. This vulnerability affects unknown code of the c... |
| CVE-2026-15525 | MEDIUM | 6.3 | 0.2% | Jul 13, 2026 | A vulnerability was detected in kLOsk adloop up to 0.9.0. This vulnerability affects the function _validate_urls of the ... |
| CVE-2026-15523 | MEDIUM | 6.3 | 0.2% | Jul 13, 2026 | A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some un... |
| CVE-2026-15522 | MEDIUM | 5.3 | 0.1% | Jul 13, 2026 | A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function v... |
| CVE-2026-15521 | MEDIUM | 5.3 | 0.1% | Jul 13, 2026 | A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. Affected is an unknown function of the fil... |
| CVE-2026-15520 | MEDIUM | 5.3 | 0.1% | Jul 13, 2026 | A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section ... |
| CVE-2026-15519 | MEDIUM | 5 | 0.2% | Jul 13, 2026 | A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the file system_prompt.jinj... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now