2026 CVE Vulnerabilities
45,220 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7655 | HIGH | 8.1 | 0.3% | Jul 11, 2026 | The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and incl... |
| CVE-2026-13378 | HIGH | 7.2 | 0.3% | Jul 11, 2026 | The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contac... |
| CVE-2026-3576 | HIGH | 7.2 | 0.4% | Jul 11, 2026 | The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local ... |
| CVE-2026-2354 | HIGH | 8.8 | 0.6% | Jul 11, 2026 | The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validatio... |
| CVE-2026-15335 | HIGH | 7.5 | 0.5% | Jul 11, 2026 | The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in ... |
| CVE-2026-14262 | HIGH | 8.8 | 0.4% | Jul 11, 2026 | The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Byp... |
| CVE-2026-15338 | HIGH | 7.5 | 0.6% | Jul 11, 2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to... |
| CVE-2026-13353 | HIGH | 8.8 | 0.6% | Jul 11, 2026 | The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remo... |
| CVE-2026-13114 | HIGH | 7.2 | 0.2% | Jul 11, 2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2026-13756 | HIGH | 8.8 | 0.3% | Jul 11, 2026 | The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3... |
| CVE-2026-55175 | HIGH | 7.5 | 0.6% | Jul 10, 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, a... |
| CVE-2026-44383 | HIGH | 8.7 | 0.6% | Jul 10, 2026 | Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to de... |
| CVE-2026-42952 | HIGH | 8.7 | 0.4% | Jul 10, 2026 | Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could al... |
| CVE-2026-57584 | HIGH | 8.7 | 0.4% | Jul 10, 2026 | Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a def... |
| CVE-2026-55883 | HIGH | 8.3 | 0.2% | Jul 10, 2026 | Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebS... |
| CVE-2026-55882 | HIGH | 8.3 | 0.4% | Jul 10, 2026 | Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD serv... |
| CVE-2026-55852 | HIGH | 8.6 | 0.5% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Imp... |
| CVE-2026-55810 | HIGH | 8.1 | 0.2% | Jul 10, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphin... |
| CVE-2026-55809 | HIGH | 8.1 | 0.3% | Jul 10, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance f... |
| CVE-2026-54736 | HIGH | 8.2 | 0.1% | Jul 10, 2026 | Phalcon is a high-performance, full-stack PHP framework. Prior to 5.14.1, Phalcon\Encryption\Crypt::decrypt compares the... |
| CVE-2026-52747 | HIGH | 8.6 | 0.5% | Jul 10, 2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to ... |
| CVE-2026-49394 | HIGH | 7.1 | 0.3% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_pag... |
| CVE-2026-49213 | HIGH | 8.1 | 0.3% | Jul 10, 2026 | TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHtt... |
| CVE-2026-44795 | HIGH | 8.8 | 1.0% | Jul 10, 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3... |
| CVE-2026-41482 | HIGH | 7.1 | 0.3% | Jul 10, 2026 | Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion wer... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now