2026 CVE Vulnerabilities
44,969 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12472 | MEDIUM | 5.3 | 0.5% | Jul 2, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypa... |
| CVE-2026-12134 | MEDIUM | 4.3 | 0.4% | Jul 2, 2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization b... |
| CVE-2026-12122 | MEDIUM | 5.3 | 0.5% | Jul 2, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Informat... |
| CVE-2026-11896 | MEDIUM | 5.3 | 0.5% | Jul 2, 2026 | The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all... |
| CVE-2026-10104 | MEDIUM | 4.4 | 0.3% | Jul 2, 2026 | The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom_t... |
| CVE-2026-5348 | MEDIUM | 5.3 | 0.3% | Jul 2, 2026 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Di... |
| CVE-2026-13704 | MEDIUM | 6.4 | 0.2% | Jul 2, 2026 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2026-13357 | MEDIUM | 4.9 | 0.3% | Jul 2, 2026 | The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions... |
| CVE-2026-11965 | MEDIUM | 6.5 | 0.1% | Jul 2, 2026 | The User Registration & Membership WordPress plugin before 5.2.0 does not enforce payment completion before activating ... |
| CVE-2026-11600 | MEDIUM | 4.3 | 0.2% | Jul 2, 2026 | The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access o... |
| CVE-2026-11592 | MEDIUM | 4.3 | 0.3% | Jul 2, 2026 | The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for W... |
| CVE-2026-10089 | MEDIUM | 6.4 | 0.2% | Jul 2, 2026 | The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key ... |
| CVE-2026-10077 | MEDIUM | 6.8 | 0.2% | Jul 2, 2026 | The yootheme WordPress theme before 5.0.35 does not prevent its bundled front-end framework from treating certain HTML a... |
| CVE-2026-55792 | MEDIUM | 6 | 0.3% | Jul 2, 2026 | Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.18.0, and 5.0.0-RC1 a... |
| CVE-2026-55791 | MEDIUM | 6.9 | 0.3% | Jul 2, 2026 | Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, ... |
| CVE-2026-50280 | MEDIUM | 6 | 0.3% | Jul 2, 2026 | Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the EntriesController::... |
| CVE-2026-50283 | MEDIUM | 5.3 | 0.3% | Jul 1, 2026 | Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain... |
| CVE-2026-14421 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potent... |
| CVE-2026-14418 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data v... |
| CVE-2026-14414 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who... |
| CVE-2026-14410 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromis... |
| CVE-2026-14408 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensit... |
| CVE-2026-14406 | MEDIUM | 5.9 | 0.2% | Jul 1, 2026 | Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allowed an attacker who convinced a user to install a m... |
| CVE-2026-14404 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Inappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI s... |
| CVE-2026-14402 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potent... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now