2026 CVE Vulnerabilities
43,937 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15471 | MEDIUM | 4.3 | 0.2% | Jul 12, 2026 | A vulnerability was found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/pci... |
| CVE-2026-15470 | MEDIUM | 4.3 | 0.2% | Jul 12, 2026 | A vulnerability has been found in Eleveo Call Recording Software 9.7.0. Affected by this issue is some unknown functiona... |
| CVE-2026-10660 | MEDIUM | 6.4 | 0.2% | Jul 11, 2026 | The Bluetooth BAP Broadcast Assistant GATT client in subsys/bluetooth/audio/bap_broadcast_assistant.c reassembled remote... |
| CVE-2026-61858 | MEDIUM | 5.3 | 0.2% | Jul 11, 2026 | ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to mis... |
| CVE-2026-61465 | MEDIUM | 6.5 | 0.2% | Jul 11, 2026 | ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed op... |
| CVE-2026-60088 | MEDIUM | 6.8 | 0.1% | Jul 11, 2026 | PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read f... |
| CVE-2026-56763 | MEDIUM | 6.3 | 0.2% | Jul 11, 2026 | Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field na... |
| CVE-2026-56296 | MEDIUM | 6.9 | 0.2% | Jul 11, 2026 | Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that ret... |
| CVE-2026-56240 | MEDIUM | 5.3 | 0.2% | Jul 11, 2026 | Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows o... |
| CVE-2026-9017 | MEDIUM | 5.3 | 0.3% | Jul 11, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all ve... |
| CVE-2026-6801 | MEDIUM | 5.3 | 0.2% | Jul 11, 2026 | The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin... |
| CVE-2026-1382 | MEDIUM | 6.4 | 0.2% | Jul 11, 2026 | The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode... |
| CVE-2026-15010 | MEDIUM | 6.4 | 0.2% | Jul 11, 2026 | The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6... |
| CVE-2026-12994 | MEDIUM | 5.3 | 0.4% | Jul 11, 2026 | The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions u... |
| CVE-2026-12738 | MEDIUM | 4.3 | 0.2% | Jul 11, 2026 | The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypas... |
| CVE-2026-12126 | MEDIUM | 6.4 | 0.2% | Jul 11, 2026 | The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2026-12103 | MEDIUM | 4.3 | 0.3% | Jul 11, 2026 | The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi... |
| CVE-2026-11901 | MEDIUM | 5.3 | 0.2% | Jul 11, 2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all version... |
| CVE-2026-11898 | MEDIUM | 4.4 | 0.2% | Jul 11, 2026 | The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions... |
| CVE-2026-11591 | MEDIUM | 4.4 | 0.3% | Jul 11, 2026 | The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a... |
| CVE-2026-10865 | MEDIUM | 5.3 | 0.4% | Jul 11, 2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, ... |
| CVE-2026-10041 | MEDIUM | 4.3 | 0.3% | Jul 11, 2026 | The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in al... |
| CVE-2026-9738 | MEDIUM | 4.4 | 0.2% | Jul 11, 2026 | The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conten... |
| CVE-2026-7620 | MEDIUM | 4.3 | 0.3% | Jul 11, 2026 | The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl... |
| CVE-2026-7559 | MEDIUM | 4.3 | 0.3% | Jul 11, 2026 | The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable to unauthorized acc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now