2026 CVE Vulnerabilities
44,805 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6371 | MEDIUM | 4.8 | 0.1% | Jul 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Limatek System Inc... |
| CVE-2026-14250 | MEDIUM | 6.3 | — | Jul 8, 2026 | The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu... |
| CVE-2026-12936 | MEDIUM | 4.9 | — | Jul 8, 2026 | The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ... |
| CVE-2026-6280 | MEDIUM | 6.5 | 0.2% | Jul 8, 2026 | Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consu... |
| CVE-2026-57259 | MEDIUM | 6.5 | 0.2% | Jul 8, 2026 | The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, th... |
| CVE-2026-57258 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underl... |
| CVE-2026-57257 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-o... |
| CVE-2026-57255 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malfo... |
| CVE-2026-57253 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an in... |
| CVE-2026-57243 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document stat... |
| CVE-2026-57241 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related... |
| CVE-2026-9731 | MEDIUM | 4.3 | 0.1% | Jul 8, 2026 | The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2026-14500 | MEDIUM | 5.3 | 0.3% | Jul 8, 2026 | The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and i... |
| CVE-2026-12097 | MEDIUM | 5.3 | 0.3% | Jul 8, 2026 | The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2... |
| CVE-2026-12041 | MEDIUM | 4.4 | 0.2% | Jul 8, 2026 | The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin ... |
| CVE-2026-11798 | MEDIUM | 6.1 | 0.2% | Jul 8, 2026 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Refle... |
| CVE-2026-10570 | MEDIUM | 6.4 | 0.2% | Jul 8, 2026 | The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repea... |
| CVE-2026-60001 | MEDIUM | 6.5 | 0.3% | Jul 8, 2026 | sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay. |
| CVE-2026-59998 | MEDIUM | 6.5 | 0.2% | Jul 8, 2026 | sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if th... |
| CVE-2026-59997 | MEDIUM | 5.4 | 0.2% | Jul 8, 2026 | internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important ... |
| CVE-2026-59996 | MEDIUM | 5.4 | 0.2% | Jul 8, 2026 | scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs betwee... |
| CVE-2026-59995 | MEDIUM | 5.4 | 0.2% | Jul 8, 2026 | sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is u... |
| CVE-2026-55438 | MEDIUM | 6.8 | 0.2% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7... |
| CVE-2026-55437 | MEDIUM | 5.4 | 0.3% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7... |
| CVE-2026-55433 | MEDIUM | 5.4 | 0.4% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now