2026 CVE Vulnerabilities
45,207 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61861 | HIGH | 7.5 | 0.3% | Jul 11, 2026 | ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in the FormatMagickCaption method when memory alloca... |
| CVE-2026-61857 | HIGH | 7.5 | 0.2% | Jul 11, 2026 | ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP p... |
| CVE-2026-61454 | HIGH | 8.7 | 0.2% | Jul 11, 2026 | The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFI... |
| CVE-2026-61442 | HIGH | 7.1 | 0.3% | Jul 11, 2026 | PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for ... |
| CVE-2026-61439 | HIGH | 8.7 | 0.3% | Jul 11, 2026 | PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults ... |
| CVE-2026-61429 | HIGH | 8.5 | 0.2% | Jul 11, 2026 | PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend th... |
| CVE-2026-61428 | HIGH | 7.3 | 0.2% | Jul 11, 2026 | PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attacke... |
| CVE-2026-61426 | HIGH | 8.8 | 0.3% | Jul 11, 2026 | PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requireme... |
| CVE-2026-56303 | HIGH | 8.7 | 0.3% | Jul 11, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function m... |
| CVE-2026-57828 | HIGH | 8.8 | 0.3% | Jul 11, 2026 | Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downlo... |
| CVE-2026-1359 | HIGH | 8.8 | 0.3% | Jul 11, 2026 | The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due t... |
| CVE-2026-9282 | HIGH | 7.5 | 0.7% | Jul 11, 2026 | The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4... |
| CVE-2026-6939 | HIGH | 7.2 | 0.3% | Jul 11, 2026 | The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app... |
| CVE-2026-4661 | HIGH | 7.5 | 0.3% | Jul 11, 2026 | The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQ... |
| CVE-2026-15155 | HIGH | 8.8 | 0.4% | Jul 11, 2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authent... |
| CVE-2026-7655 | HIGH | 8.1 | 0.3% | Jul 11, 2026 | The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and incl... |
| CVE-2026-13378 | HIGH | 7.2 | 0.3% | Jul 11, 2026 | The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contac... |
| CVE-2026-3576 | HIGH | 7.2 | 0.4% | Jul 11, 2026 | The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local ... |
| CVE-2026-2354 | HIGH | 8.8 | 0.6% | Jul 11, 2026 | The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validatio... |
| CVE-2026-15335 | HIGH | 7.5 | 0.5% | Jul 11, 2026 | The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in ... |
| CVE-2026-14262 | HIGH | 8.8 | 0.4% | Jul 11, 2026 | The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Byp... |
| CVE-2026-15338 | HIGH | 7.5 | 0.6% | Jul 11, 2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to... |
| CVE-2026-13353 | HIGH | 8.8 | 0.6% | Jul 11, 2026 | The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remo... |
| CVE-2026-13114 | HIGH | 7.2 | 0.2% | Jul 11, 2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2026-13756 | HIGH | 8.8 | 0.3% | Jul 11, 2026 | The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now