2026 CVE Vulnerabilities
45,220 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12619 | MEDIUM | 5.4 | 0.2% | Jun 19, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip G... |
| CVE-2026-21768 | MEDIUM | 6.3 | 0.1% | Jun 19, 2026 | The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to prope... |
| CVE-2026-9143 | MEDIUM | 5.3 | 0.2% | Jun 19, 2026 | There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in Co... |
| CVE-2026-49231 | MEDIUM | 5.4 | 0.4% | Jun 19, 2026 | Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upst... |
| CVE-2026-47341 | MEDIUM | 6.5 | 0.4% | Jun 19, 2026 | Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configuration... |
| CVE-2026-44915 | MEDIUM | 6.1 | 0.4% | Jun 19, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-au... |
| CVE-2026-44046 | MEDIUM | 5.8 | 0.3% | Jun 19, 2026 | Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under defaul... |
| CVE-2026-12706 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read p... |
| CVE-2026-11941 | MEDIUM | 5.6 | 0.2% | Jun 19, 2026 | Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “... |
| CVE-2026-8296 | MEDIUM | 5.6 | 0.2% | Jun 19, 2026 | In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payloa... |
| CVE-2026-56138 | MEDIUM | 5.3 | 0.3% | Jun 19, 2026 | AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item iden... |
| CVE-2026-6798 | MEDIUM | 5.3 | 0.3% | Jun 19, 2026 | The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all version... |
| CVE-2026-3640 | MEDIUM | 5.3 | 0.4% | Jun 19, 2026 | The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and ... |
| CVE-2026-9822 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, a... |
| CVE-2026-9013 | MEDIUM | 4.3 | 0.3% | Jun 19, 2026 | The Bogo plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.... |
| CVE-2026-8118 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary ... |
| CVE-2026-7547 | MEDIUM | 4.9 | 0.4% | Jun 19, 2026 | The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in ... |
| CVE-2026-56132 | MEDIUM | 6.9 | 0.1% | Jun 19, 2026 | In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array... |
| CVE-2026-56131 | MEDIUM | 4.9 | 0.1% | Jun 19, 2026 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a... |
| CVE-2026-4328 | MEDIUM | 6.4 | 0.2% | Jun 19, 2026 | The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includi... |
| CVE-2026-1856 | MEDIUM | 6.4 | 0.2% | Jun 19, 2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking fi... |
| CVE-2026-12644 | MEDIUM | 5.5 | 0.3% | Jun 19, 2026 | Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of b... |
| CVE-2026-12430 | MEDIUM | 4.4 | 0.2% | Jun 19, 2026 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio... |
| CVE-2026-12157 | MEDIUM | 6.4 | 0.2% | Jun 19, 2026 | The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to S... |
| CVE-2026-11989 | MEDIUM | 6.5 | 0.3% | Jun 19, 2026 | The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vuln... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now