2026 CVE Vulnerabilities
44,067 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-60094 | MEDIUM | 6.9 | 0.4% | Jul 9, 2026 | Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated ... |
| CVE-2026-15186 | MEDIUM | 6.3 | — | Jul 9, 2026 | A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply... |
| CVE-2026-12879 | MEDIUM | 5.9 | — | Jul 9, 2026 | An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google... |
| CVE-2026-15182 | MEDIUM | 5.3 | — | Jul 9, 2026 | A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file sr... |
| CVE-2026-9240 | MEDIUM | 4.3 | — | Jul 9, 2026 | The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2026-9237 | MEDIUM | 4.3 | — | Jul 9, 2026 | The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization byp... |
| CVE-2026-9235 | MEDIUM | 4.3 | — | Jul 9, 2026 | The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of ... |
| CVE-2026-9028 | MEDIUM | 5.3 | — | Jul 9, 2026 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up ... |
| CVE-2026-9027 | MEDIUM | 5.3 | — | Jul 9, 2026 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification... |
| CVE-2026-9021 | MEDIUM | 5.3 | — | Jul 9, 2026 | The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. T... |
| CVE-2026-58307 | MEDIUM | 6.1 | — | Jul 9, 2026 | Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Dat... |
| CVE-2026-58306 | MEDIUM | 6.1 | — | Jul 9, 2026 | Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Es... |
| CVE-2026-58305 | MEDIUM | 6.1 | — | Jul 9, 2026 | Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Point... |
| CVE-2026-58304 | MEDIUM | 6.1 | — | Jul 9, 2026 | Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This iss... |
| CVE-2026-58303 | MEDIUM | 6.1 | — | Jul 9, 2026 | Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects E... |
| CVE-2026-56289 | MEDIUM | 5.5 | 0.1% | Jul 9, 2026 | GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff... |
| CVE-2026-56288 | MEDIUM | 5.5 | 0.1% | Jul 9, 2026 | GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Impro... |
| CVE-2026-4298 | MEDIUM | 4.3 | — | Jul 9, 2026 | The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and includ... |
| CVE-2026-12590 | MEDIUM | 5.9 | — | Jul 9, 2026 | Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an i... |
| CVE-2026-12428 | MEDIUM | 6.5 | — | Jul 9, 2026 | The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ... |
| CVE-2026-5793 | MEDIUM | 6.1 | 0.3% | Jul 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software an... |
| CVE-2026-56460 | MEDIUM | 6.5 | 0.4% | Jul 9, 2026 | HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API respons... |
| CVE-2026-56459 | MEDIUM | 5.5 | 0.2% | Jul 9, 2026 | HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially s... |
| CVE-2026-1365 | MEDIUM | 6.5 | 0.4% | Jul 9, 2026 | Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentica... |
| CVE-2026-12433 | MEDIUM | 4.3 | 0.4% | Jul 9, 2026 | The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Obje... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now