2026 CVE Vulnerabilities
46,942 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6820 | HIGH | 7.2 | — | Jul 8, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ema... |
| CVE-2026-5356 | HIGH | 7.5 | — | Jul 8, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input... |
| CVE-2026-6854 | HIGH | 7.5 | — | Jul 8, 2026 | The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the ... |
| CVE-2026-6818 | HIGH | 7.2 | — | Jul 8, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spe... |
| CVE-2026-6230 | HIGH | 7.5 | — | Jul 8, 2026 | The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all ve... |
| CVE-2026-3688 | HIGH | 8.1 | — | Jul 8, 2026 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure... |
| CVE-2026-56003 | HIGH | 8.8 | 0.6% | Jul 8, 2026 | A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeSc... |
| CVE-2026-56002 | HIGH | 8.8 | 0.5% | Jul 8, 2026 | A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers auth... |
| CVE-2026-57260 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly re... |
| CVE-2026-57256 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and thi... |
| CVE-2026-57254 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF,... |
| CVE-2026-57252 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotatio... |
| CVE-2026-57251 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper ... |
| CVE-2026-57250 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlyi... |
| CVE-2026-57249 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form e... |
| CVE-2026-57248 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object ... |
| CVE-2026-57247 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The application re-enters the document structure via field processing and deletes the current page, and then continues u... |
| CVE-2026-57246 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature ... |
| CVE-2026-57245 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to valida... |
| CVE-2026-57244 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verifica... |
| CVE-2026-57242 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete ... |
| CVE-2026-57240 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old fie... |
| CVE-2026-57239 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege use... |
| CVE-2026-57238 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the... |
| CVE-2026-57237 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the under... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now