2026 CVE Vulnerabilities
44,964 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9180 | MEDIUM | 5.3 | 0.3% | Jul 3, 2026 | The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key... |
| CVE-2026-8892 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2026-8489 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2026-12557 | MEDIUM | 5.3 | 0.2% | Jul 3, 2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc... |
| CVE-2026-11397 | MEDIUM | 5.5 | 0.2% | Jul 3, 2026 | The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and in... |
| CVE-2026-12960 | MEDIUM | 6 | 0.1% | Jul 3, 2026 | An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application o... |
| CVE-2026-12920 | MEDIUM | 4.9 | 0.3% | Jul 3, 2026 | The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via ... |
| CVE-2026-12734 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stor... |
| CVE-2026-12731 | MEDIUM | 6.4 | 0.2% | Jul 3, 2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stor... |
| CVE-2026-12729 | MEDIUM | 4.3 | 0.2% | Jul 3, 2026 | The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Miss... |
| CVE-2026-55726 | MEDIUM | 6.9 | 0.4% | Jul 3, 2026 | The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious us... |
| CVE-2026-54477 | MEDIUM | 5.4 | 0.2% | Jul 3, 2026 | The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks. |
| CVE-2026-13728 | MEDIUM | 4.4 | 0.1% | Jul 3, 2026 | In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved... |
| CVE-2026-13377 | MEDIUM | 4.8 | 0.2% | Jul 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2026-13376 | MEDIUM | 4.8 | 0.2% | Jul 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2026-13375 | MEDIUM | 4.8 | 0.2% | Jul 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2026-13374 | MEDIUM | 4.8 | 0.2% | Jul 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2026-13373 | MEDIUM | 4.8 | 0.2% | Jul 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2026-13371 | MEDIUM | 4.9 | 0.3% | Jul 3, 2026 | An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending ma... |
| CVE-2026-50722 | MEDIUM | 5.9 | 0.3% | Jul 2, 2026 | Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding o... |
| CVE-2026-50721 | MEDIUM | 5.9 | 0.4% | Jul 2, 2026 | Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authen... |
| CVE-2026-52188 | MEDIUM | 6.5 | 0.2% | Jul 2, 2026 | Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s... |
| CVE-2026-59102 | MEDIUM | 5.4 | 0.2% | Jul 2, 2026 | Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execut... |
| CVE-2026-59101 | MEDIUM | 6.9 | 0.3% | Jul 2, 2026 | AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote ... |
| CVE-2026-59100 | MEDIUM | 5 | 0.2% | Jul 2, 2026 | LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now