2026 CVE Vulnerabilities
44,996 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58078 | HIGH | 8.7 | 0.2% | Jul 16, 2026 | Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extensio... |
| CVE-2026-15103 | HIGH | 8.8 | 0.3% | Jul 16, 2026 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Pr... |
| CVE-2026-15008 | HIGH | 8.1 | 0.6% | Jul 16, 2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnera... |
| CVE-2026-15005 | HIGH | 8.8 | — | Jul 16, 2026 | The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2026-13741 | HIGH | 8.8 | 0.2% | Jul 16, 2026 | The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all v... |
| CVE-2026-12978 | HIGH | 7.1 | — | Jul 16, 2026 | The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the ... |
| CVE-2026-12585 | HIGH | 8.1 | 0.1% | Jul 16, 2026 | The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recover... |
| CVE-2026-12525 | HIGH | 8.8 | 0.1% | Jul 16, 2026 | The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving cus... |
| CVE-2026-53366 | HIGH | 7.8 | 0.2% | Jul 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation p... |
| CVE-2026-13042 | HIGH | 7.2 | 0.2% | Jul 16, 2026 | The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions... |
| CVE-2026-21729 | HIGH | 7.5 | 0.3% | Jul 16, 2026 | Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depe... |
| CVE-2026-12753 | HIGH | 7.5 | 0.3% | Jul 16, 2026 | The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Inject... |
| CVE-2026-48863 | HIGH | 7.5 | 0.8% | Jul 16, 2026 | A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to... |
| CVE-2026-3842 | HIGH | 7.8 | 0.1% | Jul 16, 2026 | A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond... |
| CVE-2026-23538 | HIGH | 7.5 | 0.7% | Jul 16, 2026 | A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establi... |
| CVE-2026-1609 | HIGH | 8.1 | 0.5% | Jul 16, 2026 | A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user ac... |
| CVE-2026-15907 | HIGH | 7.3 | 0.3% | Jul 16, 2026 | A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=... |
| CVE-2026-63175 | HIGH | 7.1 | 0.3% | Jul 15, 2026 | PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than in... |
| CVE-2026-55576 | HIGH | 8.8 | 0.3% | Jul 15, 2026 | MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/r... |
| CVE-2026-55234 | HIGH | 8.5 | 0.2% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.j... |
| CVE-2026-53445 | HIGH | 7.1 | 0.2% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publicatio... |
| CVE-2026-53444 | HIGH | 7.6 | 0.2% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/o... |
| CVE-2026-52890 | HIGH | 7.1 | 0.3% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachm... |
| CVE-2026-49279 | HIGH | 7.7 | 0.3% | Jul 15, 2026 | WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the aut... |
| CVE-2026-48795 | HIGH | 8.6 | 0.5% | Jul 15, 2026 | AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now