2026 CVE Vulnerabilities
45,449 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57895 | HIGH | 8.5 | 0.1% | Jul 8, 2026 | Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executa... |
| CVE-2026-56437 | HIGH | 8.4 | 0.1% | Jul 8, 2026 | Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the... |
| CVE-2026-14495 | HIGH | 8.8 | 0.4% | Jul 8, 2026 | The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all vers... |
| CVE-2026-14489 | HIGH | 8.8 | 0.6% | Jul 8, 2026 | The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the... |
| CVE-2026-9842 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,... |
| CVE-2026-14482 | HIGH | 8.8 | 0.3% | Jul 8, 2026 | The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The v... |
| CVE-2026-14244 | HIGH | 7.5 | 0.7% | Jul 8, 2026 | The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu... |
| CVE-2026-14158 | HIGH | 8.8 | 0.5% | Jul 8, 2026 | The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including... |
| CVE-2026-60000 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive au... |
| CVE-2026-59999 | HIGH | 7.5 | 0.1% | Jul 8, 2026 | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not... |
| CVE-2026-55436 | HIGH | 7.4 | 0.3% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and pr... |
| CVE-2026-55429 | HIGH | 8.7 | 0.5% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55428 | HIGH | 8.2 | 0.4% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55427 | HIGH | 8.3 | 0.5% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-59704 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metada... |
| CVE-2026-55077 | HIGH | 7.2 | 0.6% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55076 | HIGH | 7.4 | 0.5% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-51937 | HIGH | 7.5 | 0.4% | Jul 7, 2026 | An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsAp... |
| CVE-2026-14895 | HIGH | 7.5 | 0.2% | Jul 7, 2026 | String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtri... |
| CVE-2026-14380 | HIGH | 8.8 | 0.5% | Jul 7, 2026 | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is ass... |
| CVE-2026-55418 | HIGH | 8.6 | 0.3% | Jul 7, 2026 | FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unr... |
| CVE-2026-55408 | HIGH | 8.4 | 0.2% | Jul 7, 2026 | Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution throu... |
| CVE-2026-55075 | HIGH | 7.4 | 0.5% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-54607 | HIGH | 7.7 | 0.2% | Jul 7, 2026 | FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer valid... |
| CVE-2026-54602 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now