2026 CVE Vulnerabilities
44,049 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56373 | MEDIUM | 5.3 | 0.2% | Jul 10, 2026 | ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when me... |
| CVE-2026-56366 | MEDIUM | 6.5 | 0.1% | Jul 10, 2026 | ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths... |
| CVE-2026-56354 | MEDIUM | 5.4 | 0.2% | Jul 10, 2026 | n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirec... |
| CVE-2026-56329 | MEDIUM | 6.4 | — | Jul 10, 2026 | Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding... |
| CVE-2026-56312 | MEDIUM | 6.9 | — | Jul 10, 2026 | Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user ... |
| CVE-2026-56309 | MEDIUM | 5.4 | — | Jul 10, 2026 | Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-... |
| CVE-2026-54470 | MEDIUM | 5.3 | 0.2% | Jul 10, 2026 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Ref... |
| CVE-2026-56814 | MEDIUM | 6.9 | — | Jul 10, 2026 | Plug.Parsers.MULTIPART, the multipart request-body parser used to handle file uploads and multipart forms, does not enfo... |
| CVE-2026-54468 | MEDIUM | 6.5 | 0.3% | Jul 10, 2026 | Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged ... |
| CVE-2026-14461 | MEDIUM | 5.1 | — | Jul 10, 2026 | mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT ... |
| CVE-2026-9857 | MEDIUM | 4.3 | 0.5% | Jul 10, 2026 | The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. T... |
| CVE-2026-41877 | MEDIUM | 5.1 | 0.4% | Jul 10, 2026 | R-SOFT DMS is vulnerable to Stored XSS in file upload functionality. Authenticated attacker can inject arbitrary HTML an... |
| CVE-2026-13710 | MEDIUM | 6.4 | 0.4% | Jul 10, 2026 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul... |
| CVE-2026-13247 | MEDIUM | 6.4 | 0.3% | Jul 10, 2026 | The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to... |
| CVE-2026-13010 | MEDIUM | 6.5 | 0.4% | Jul 10, 2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL ... |
| CVE-2026-12918 | MEDIUM | 4.9 | 0.3% | Jul 10, 2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to... |
| CVE-2026-11990 | MEDIUM | 5.3 | 0.6% | Jul 10, 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in al... |
| CVE-2026-9838 | MEDIUM | 6.1 | 0.3% | Jul 10, 2026 | The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter i... |
| CVE-2026-6802 | MEDIUM | 5.3 | 0.2% | Jul 10, 2026 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, a... |
| CVE-2026-6440 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cro... |
| CVE-2026-3907 | MEDIUM | 6.4 | 0.2% | Jul 10, 2026 | The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all ve... |
| CVE-2026-1946 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2026-15104 | MEDIUM | 6.5 | 0.3% | Jul 10, 2026 | The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to g... |
| CVE-2026-15026 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve... |
| CVE-2026-14475 | MEDIUM | 4.9 | 0.3% | Jul 10, 2026 | The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now