2026 CVE Vulnerabilities
44,976 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53333 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/mincore: handle non-swap entries before !CONFIG_... |
| CVE-2026-53332 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Register callbacks after cr... |
| CVE-2026-53331 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl-... |
| CVE-2026-53328 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Don't warn on NULL cgrp_moving_from in s... |
| CVE-2026-53327 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: debugobjects: Do not fill_pool() if pi_blocked_on ... |
| CVE-2026-53326 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: debugobjects: Don't call fill_pool() in early boot ... |
| CVE-2026-53909 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side... |
| CVE-2026-53908 | MEDIUM | 4.3 | 0.3% | Jul 1, 2026 | MCO is vulnerable to User Enumeration through authentication-related functionalities. The application returns distinguis... |
| CVE-2026-53907 | MEDIUM | 5.4 | 0.3% | Jul 1, 2026 | MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with t... |
| CVE-2026-53902 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership... |
| CVE-2026-14258 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially crafted IPv6 Router Ad... |
| CVE-2026-10095 | MEDIUM | 6.4 | — | Jul 1, 2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in... |
| CVE-2026-27435 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Securit... |
| CVE-2026-13454 | MEDIUM | 6.5 | 0.4% | Jul 1, 2026 | The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in a... |
| CVE-2026-12754 | MEDIUM | 6.1 | 0.3% | Jul 1, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '... |
| CVE-2026-56016 | MEDIUM | 5.9 | 0.3% | Jul 1, 2026 | CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The gene... |
| CVE-2026-13733 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attri... |
| CVE-2026-12732 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode ... |
| CVE-2026-12435 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in a... |
| CVE-2026-12408 | MEDIUM | 4.3 | 0.3% | Jul 1, 2026 | The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to Unauthorized Private Co... |
| CVE-2026-10540 | MEDIUM | 5.6 | 0.1% | Jul 1, 2026 | The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offl... |
| CVE-2026-10096 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin... |
| CVE-2026-11887 | MEDIUM | 4.3 | 0.1% | Jul 1, 2026 | The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX ... |
| CVE-2026-11570 | MEDIUM | 4.2 | 0.2% | Jul 1, 2026 | The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an ... |
| CVE-2026-11562 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions,... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now