2026 CVE Vulnerabilities
45,066 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13437 | MEDIUM | 6.5 | 0.3% | Jun 29, 2026 | Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 a... |
| CVE-2026-57341 | MEDIUM | 6.5 | 0.3% | Jun 29, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce ... |
| CVE-2026-57340 | MEDIUM | 6.5 | — | Jun 29, 2026 | Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions. |
| CVE-2026-57339 | MEDIUM | 6.5 | — | Jun 29, 2026 | Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions. |
| CVE-2026-57335 | MEDIUM | 6.5 | 0.2% | Jun 29, 2026 | Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions. |
| CVE-2026-57334 | MEDIUM | 6.5 | — | Jun 29, 2026 | Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. |
| CVE-2026-57330 | MEDIUM | 6.5 | — | Jun 29, 2026 | Subscriber Cross Site Scripting (XSS) in MasterStudy LMS <= 3.7.27 versions. |
| CVE-2026-57329 | MEDIUM | 6.5 | 0.2% | Jun 29, 2026 | Subscriber Cross Site Scripting (XSS) in WooCommerce Designer Pro <= 1.9.34 versions. |
| CVE-2026-57328 | MEDIUM | 6.5 | — | Jun 29, 2026 | Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions. |
| CVE-2026-57327 | MEDIUM | 6.3 | — | Jun 29, 2026 | Subscriber Broken Access Control in MainWP <= 6.1.1 versions. |
| CVE-2026-57326 | MEDIUM | 6.1 | — | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions. |
| CVE-2026-46406 | MEDIUM | 6.1 | 0.2% | Jun 29, 2026 | Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a ha... |
| CVE-2026-13579 | MEDIUM | 6.3 | — | Jun 29, 2026 | A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown fu... |
| CVE-2026-13578 | MEDIUM | 6.3 | — | Jun 29, 2026 | A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an... |
| CVE-2026-13572 | MEDIUM | 6.3 | 0.2% | Jun 29, 2026 | A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown functi... |
| CVE-2026-13571 | MEDIUM | 5.5 | — | Jun 29, 2026 | A flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of ... |
| CVE-2026-56457 | MEDIUM | 4.3 | 0.2% | Jun 29, 2026 | HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This... |
| CVE-2026-13569 | MEDIUM | 4.7 | — | Jun 29, 2026 | A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processin... |
| CVE-2026-13567 | MEDIUM | 4.3 | — | Jun 29, 2026 | A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Fr... |
| CVE-2026-12616 | MEDIUM | 6.9 | — | Jun 29, 2026 | The /v1/upload/sbom endpoint extracts the iss claim from the attacker-supplied JWT with signature verification disabled,... |
| CVE-2026-41991 | MEDIUM | 4.7 | 0.1% | Jun 29, 2026 | GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp util... |
| CVE-2026-13561 | MEDIUM | 6.3 | — | Jun 29, 2026 | A vulnerability was detected in Edimax EW-7478APC 1.04. The impacted element is the function formiNICbasic of the file /... |
| CVE-2026-13560 | MEDIUM | 6.3 | 1.2% | Jun 29, 2026 | A security vulnerability has been detected in Edimax EW-7478APC 1.04. The affected element is the function formAccept of... |
| CVE-2026-13601 | MEDIUM | 6.5 | 0.1% | Jun 29, 2026 | A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. ... |
| CVE-2026-13557 | MEDIUM | 4.3 | — | Jun 29, 2026 | A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown co... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now