2026 CVE Vulnerabilities
44,054 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1946 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2026-15104 | MEDIUM | 6.5 | 0.3% | Jul 10, 2026 | The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to g... |
| CVE-2026-15026 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve... |
| CVE-2026-14475 | MEDIUM | 4.9 | 0.3% | Jul 10, 2026 | The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via ... |
| CVE-2026-12955 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil... |
| CVE-2026-12924 | MEDIUM | 6.4 | 0.2% | Jul 10, 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to S... |
| CVE-2026-12400 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in al... |
| CVE-2026-12108 | MEDIUM | 4.4 | 0.2% | Jul 10, 2026 | The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ... |
| CVE-2026-11992 | MEDIUM | 4.3 | 0.3% | Jul 10, 2026 | The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3... |
| CVE-2026-40009 | MEDIUM | 6.5 | 0.1% | Jul 10, 2026 | Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate t... |
| CVE-2026-12276 | MEDIUM | 5.3 | 0.1% | Jul 10, 2026 | The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enable... |
| CVE-2026-12123 | MEDIUM | 6.4 | 0.2% | Jul 10, 2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an... |
| CVE-2026-21057 | MEDIUM | 6.8 | 0.1% | Jul 10, 2026 | Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bo... |
| CVE-2026-21056 | MEDIUM | 4.8 | 0.1% | Jul 10, 2026 | Improper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device i... |
| CVE-2026-21054 | MEDIUM | 6.9 | 0.1% | Jul 10, 2026 | Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to ac... |
| CVE-2026-21053 | MEDIUM | 5.1 | 0.1% | Jul 10, 2026 | Improper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files wi... |
| CVE-2026-21052 | MEDIUM | 6.8 | 0.1% | Jul 10, 2026 | Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files ... |
| CVE-2026-21051 | MEDIUM | 5.1 | 0.1% | Jul 10, 2026 | Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure Tence... |
| CVE-2026-21050 | MEDIUM | 5.1 | 0.1% | Jul 10, 2026 | Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive inf... |
| CVE-2026-21044 | MEDIUM | 5.8 | 0.1% | Jul 10, 2026 | Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persiste... |
| CVE-2026-21043 | MEDIUM | 6.7 | 0.1% | Jul 10, 2026 | Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files wi... |
| CVE-2026-21041 | MEDIUM | 6.9 | 0.1% | Jul 10, 2026 | Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensit... |
| CVE-2026-21040 | MEDIUM | 6.9 | 0.1% | Jul 10, 2026 | Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the priv... |
| CVE-2026-21039 | MEDIUM | 6.9 | 0.1% | Jul 10, 2026 | Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection... |
| CVE-2026-15332 | MEDIUM | 6.3 | 0.2% | Jul 10, 2026 | A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an unknown function of the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now