2026 CVE Vulnerabilities
45,121 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9183 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up t... |
| CVE-2026-9175 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorizati... |
| CVE-2026-9172 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modifi... |
| CVE-2026-8905 | MEDIUM | 6.1 | 0.1% | Jun 24, 2026 | The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2026-8896 | MEDIUM | 6.4 | 0.2% | Jun 24, 2026 | The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribut... |
| CVE-2026-8865 | MEDIUM | 6.4 | 0.2% | Jun 24, 2026 | The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '... |
| CVE-2026-8690 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions... |
| CVE-2026-8688 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu... |
| CVE-2026-8628 | MEDIUM | 6.1 | 0.2% | Jun 24, 2026 | The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all ver... |
| CVE-2026-8622 | MEDIUM | 6.1 | 0.2% | Jun 24, 2026 | The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Varia... |
| CVE-2026-8617 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, a... |
| CVE-2026-8614 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check a... |
| CVE-2026-7617 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7.... |
| CVE-2026-6292 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up t... |
| CVE-2026-12094 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a mi... |
| CVE-2026-11997 | MEDIUM | 4.3 | 0.1% | Jun 24, 2026 | The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.... |
| CVE-2026-11370 | MEDIUM | 6.4 | 0.2% | Jun 24, 2026 | The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ... |
| CVE-2026-10552 | MEDIUM | 4.3 | 0.1% | Jun 24, 2026 | The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1.... |
| CVE-2026-10531 | MEDIUM | 5.4 | 0.1% | Jun 24, 2026 | The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes bef... |
| CVE-2026-9539 | MEDIUM | 6.5 | 0.1% | Jun 24, 2026 | An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp... |
| CVE-2026-12488 | MEDIUM | 6.2 | 0.2% | Jun 24, 2026 | A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2. A specially cr... |
| CVE-2026-11614 | MEDIUM | 6.4 | 0.3% | Jun 24, 2026 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '... |
| CVE-2026-6458 | MEDIUM | 5.1 | 0.1% | Jun 24, 2026 | Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authenticat... |
| CVE-2026-48493 | MEDIUM | 5.5 | 0.2% | Jun 23, 2026 | Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PA... |
| CVE-2026-47693 | MEDIUM | 6.9 | 0.2% | Jun 23, 2026 | Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now