2026 CVE Vulnerabilities
44,991 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11570 | MEDIUM | 4.2 | 0.2% | Jul 1, 2026 | The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an ... |
| CVE-2026-11562 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions,... |
| CVE-2026-9107 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2026-7828 | MEDIUM | 5.3 | 0.8% | Jul 1, 2026 | UltraVNC repeater through 1.8.2.2 contains an integer overflow in the HTTP request logging path. In repeater/webgui/sett... |
| CVE-2026-58519 | MEDIUM | 5.4 | 0.3% | Jul 1, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun... |
| CVE-2026-58518 | MEDIUM | 6.3 | 0.2% | Jul 1, 2026 | Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows... |
| CVE-2026-44041 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | UltraVNC through 1.8.2.2 contains an out-of-bounds read in the wide-string to multibyte conversion helper. In rfb/dh.cpp... |
| CVE-2026-44040 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | UltraVNC through 1.8.2.2 uses a cryptographically weak pseudo-random number generator to produce VNC authentication chal... |
| CVE-2026-2387 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi... |
| CVE-2026-13443 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2026-13246 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2026-13015 | MEDIUM | 6.1 | 0.2% | Jul 1, 2026 | The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' ... |
| CVE-2026-12904 | MEDIUM | 4.3 | 0.3% | Jul 1, 2026 | The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulnerable to Insecure Direct Ob... |
| CVE-2026-12902 | MEDIUM | 4.3 | 0.3% | Jul 1, 2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypas... |
| CVE-2026-12135 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' ... |
| CVE-2026-12133 | MEDIUM | 4.3 | 0.3% | Jul 1, 2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authori... |
| CVE-2026-12127 | MEDIUM | 5.3 | 0.3% | Jul 1, 2026 | The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu... |
| CVE-2026-12113 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up... |
| CVE-2026-12110 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to gene... |
| CVE-2026-12090 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to gene... |
| CVE-2026-11988 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure ... |
| CVE-2026-11981 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 Thi... |
| CVE-2026-11380 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and inc... |
| CVE-2026-20463 | MEDIUM | 6.7 | 0.1% | Jul 1, 2026 | In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation o... |
| CVE-2026-20462 | MEDIUM | 6.7 | 0.1% | Jul 1, 2026 | In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation o... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now