2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19328 | MEDIUM | 5.3 | 0.1% | Aug 9, 2026 | A vulnerability has been found in aktsmm skill-ninja-mcp-server 0.1.0. Impacted is the function getInstalledSkills/insta... |
| CVE-2026-19327 | MEDIUM | 5.3 | 0.1% | Aug 9, 2026 | A flaw has been found in abracadabra50 claude-sesh 1.0.0. This issue affects the function getEnrichedData/enrichSession ... |
| CVE-2026-19326 | MEDIUM | 4.4 | 0.1% | Aug 9, 2026 | A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the ... |
| CVE-2026-19325 | MEDIUM | 5.3 | 0.1% | Aug 9, 2026 | A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35a... |
| CVE-2026-19323 | MEDIUM | 5.3 | 0.1% | Aug 9, 2026 | A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected ... |
| CVE-2026-71502 | MEDIUM | 5.1 | 0.6% | Aug 8, 2026 | CTI-Transmute contains a stored cross-site scripting vulnerability caused by insufficient neutralization of Vue template... |
| CVE-2026-19288 | MEDIUM | 5.3 | 0.1% | Aug 8, 2026 | A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This ... |
| CVE-2026-19287 | MEDIUM | 5.3 | 0.1% | Aug 8, 2026 | A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the com... |
| CVE-2026-19285 | MEDIUM | 5.3 | 0.1% | Aug 8, 2026 | A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vu... |
| CVE-2026-19284 | MEDIUM | 5.3 | 0.6% | Aug 8, 2026 | A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProje... |
| CVE-2026-19282 | MEDIUM | 5.3 | 0.6% | Aug 8, 2026 | A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts... |
| CVE-2026-19281 | MEDIUM | 5.3 | 0.6% | Aug 8, 2026 | A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generate... |
| CVE-2026-19279 | MEDIUM | 5.3 | 0.7% | Aug 8, 2026 | A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the fi... |
| CVE-2026-19270 | MEDIUM | 5.3 | 0.1% | Aug 8, 2026 | A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_jo... |
| CVE-2026-19268 | MEDIUM | 6.3 | 1.1% | Aug 8, 2026 | A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts t... |
| CVE-2026-19266 | MEDIUM | 5.5 | 1.5% | Aug 8, 2026 | A vulnerability was determined in Kirachon context-engine up to 1.9.0. This affects the function execGitCommand of the f... |
| CVE-2026-19259 | MEDIUM | 5.3 | 0.1% | Aug 8, 2026 | A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping... |
| CVE-2026-16955 | MEDIUM | 5 | 0.2% | Aug 8, 2026 | The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwardi... |
| CVE-2026-16953 | MEDIUM | 4.8 | 0.1% | Aug 8, 2026 | The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deleti... |
| CVE-2026-16608 | MEDIUM | 5.3 | 0.1% | Aug 8, 2026 | The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging ... |
| CVE-2026-16595 | MEDIUM | 6.5 | 0.1% | Aug 8, 2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti... |
| CVE-2026-16590 | MEDIUM | 6.5 | 0.1% | Aug 8, 2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti... |
| CVE-2026-16574 | MEDIUM | 5.4 | 0.1% | Aug 8, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that ... |
| CVE-2026-16562 | MEDIUM | 6.5 | 0.1% | Aug 8, 2026 | The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics ... |
| CVE-2026-16559 | MEDIUM | 6.8 | 0.2% | Aug 8, 2026 | The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload featur... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now