2026 CVE Vulnerabilities
45,099 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57389 | HIGH | 8.6 | 0.5% | Jul 13, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg ... |
| CVE-2026-57388 | HIGH | 7.1 | 0.3% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Boo... |
| CVE-2026-57387 | HIGH | 7.1 | 0.3% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in picu picu picu all... |
| CVE-2026-57386 | HIGH | 8.8 | 0.4% | Jul 13, 2026 | Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affec... |
| CVE-2026-57385 | HIGH | 8.5 | 0.4% | Jul 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vit... |
| CVE-2026-57383 | HIGH | 7.1 | 0.3% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch w... |
| CVE-2026-57382 | HIGH | 7.1 | 0.3% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Si... |
| CVE-2026-57381 | HIGH | 7.1 | 0.3% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive Prop... |
| CVE-2026-57380 | HIGH | 7.1 | 0.3% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions ... |
| CVE-2026-57379 | HIGH | 7.1 | 0.3% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat s... |
| CVE-2026-57378 | HIGH | 7.5 | 0.3% | Jul 13, 2026 | Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured... |
| CVE-2026-57376 | HIGH | 7.1 | 0.3% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader El... |
| CVE-2026-57372 | HIGH | 7.2 | 0.3% | Jul 13, 2026 | Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.... |
| CVE-2026-57371 | HIGH | 8.8 | 0.5% | Jul 13, 2026 | Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue a... |
| CVE-2026-57369 | HIGH | 7.1 | 0.3% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify ... |
| CVE-2026-57368 | HIGH | 7.1 | 0.3% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonste... |
| CVE-2026-57363 | HIGH | 7.1 | 0.3% | Jul 13, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatB... |
| CVE-2026-22100 | HIGH | 8.6 | 1.0% | Jul 13, 2026 | The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitra... |
| CVE-2026-22099 | HIGH | 8.7 | 0.2% | Jul 13, 2026 | The charging station does not require authentication for Bluetooth commands to perform actions. The functionality expose... |
| CVE-2026-15557 | HIGH | 7.3 | 0.5% | Jul 13, 2026 | A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInterna... |
| CVE-2026-15548 | HIGH | 8.8 | 0.7% | Jul 13, 2026 | A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub... |
| CVE-2026-62143 | HIGH | 8.3 | 0.2% | Jul 13, 2026 | A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules.... |
| CVE-2026-15574 | HIGH | 7.5 | 0.3% | Jul 13, 2026 | A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorizat... |
| CVE-2026-15545 | HIGH | 8.8 | 0.4% | Jul 13, 2026 | A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of ... |
| CVE-2026-15544 | HIGH | 8.8 | 0.4% | Jul 13, 2026 | A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now