2026 CVE Vulnerabilities
45,269 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56009 | MEDIUM | 5.9 | 0.1% | Jun 18, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bri... |
| CVE-2026-56007 | MEDIUM | 5.9 | 0.1% | Jun 18, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Prod... |
| CVE-2026-54221 | MEDIUM | 5.1 | 0.3% | Jun 18, 2026 | UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling ... |
| CVE-2026-54219 | MEDIUM | 5.1 | 0.3% | Jun 18, 2026 | UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly saniti... |
| CVE-2026-44942 | MEDIUM | 6.5 | 0.3% | Jun 18, 2026 | A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series... |
| CVE-2026-42490 | MEDIUM | 6.5 | 0.2% | Jun 18, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-42489 | MEDIUM | 5.3 | 0.1% | Jun 18, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-12539 | MEDIUM | 5.7 | 0.1% | Jun 18, 2026 | Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-appl... |
| CVE-2026-12527 | MEDIUM | 6 | 0.2% | Jun 18, 2026 | A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V3... |
| CVE-2026-12039 | MEDIUM | 5.7 | 0.1% | Jun 18, 2026 | Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network... |
| CVE-2026-8039 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attr... |
| CVE-2026-50643 | MEDIUM | 5.1 | 0.1% | Jun 18, 2026 | 8cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU linemarkers. The compile... |
| CVE-2026-2021 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortc... |
| CVE-2026-9815 | MEDIUM | 6.5 | 0.2% | Jun 18, 2026 | The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenti... |
| CVE-2026-55745 | MEDIUM | 5.4 | 0.1% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ... |
| CVE-2026-28573 | MEDIUM | 5.5 | 0.1% | Jun 18, 2026 | In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could l... |
| CVE-2026-12137 | MEDIUM | 6.1 | 0.2% | Jun 18, 2026 | The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is... |
| CVE-2026-12136 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysb... |
| CVE-2026-12111 | MEDIUM | 4.3 | 0.3% | Jun 18, 2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to,... |
| CVE-2026-12098 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'embed... |
| CVE-2026-9199 | MEDIUM | 4.3 | 0.2% | Jun 18, 2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl... |
| CVE-2026-12120 | MEDIUM | 5.3 | 0.3% | Jun 18, 2026 | The FireBox Popups – Increase Sales and Grow Your Email List plugin for WordPress is vulnerable to Sensitive Information... |
| CVE-2026-12093 | MEDIUM | 5.3 | 0.4% | Jun 18, 2026 | The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4... |
| CVE-2026-11784 | MEDIUM | 4.3 | 0.2% | Jun 18, 2026 | The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vuln... |
| CVE-2026-11777 | MEDIUM | 4.9 | 0.4% | Jun 18, 2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to generic... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now