2026 CVE Vulnerabilities
46,943 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56001 | HIGH | 8.8 | 0.4% | Jul 8, 2026 | A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by... |
| CVE-2026-56000 | HIGH | 7.8 | 0.2% | Jul 8, 2026 | Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland b... |
| CVE-2026-55999 | HIGH | 7.8 | 0.3% | Jul 8, 2026 | Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland b... |
| CVE-2026-13129 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in t... |
| CVE-2026-13128 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the... |
| CVE-2026-13127 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the... |
| CVE-2026-13126 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a ... |
| CVE-2026-12378 | HIGH | 8.1 | 0.2% | Jul 8, 2026 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data be... |
| CVE-2026-9700 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up t... |
| CVE-2026-57895 | HIGH | 8.5 | 0.1% | Jul 8, 2026 | Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executa... |
| CVE-2026-56437 | HIGH | 8.4 | 0.1% | Jul 8, 2026 | Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the... |
| CVE-2026-14495 | HIGH | 8.8 | 0.4% | Jul 8, 2026 | The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all vers... |
| CVE-2026-14489 | HIGH | 8.8 | 0.6% | Jul 8, 2026 | The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the... |
| CVE-2026-9842 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,... |
| CVE-2026-14482 | HIGH | 8.8 | 0.3% | Jul 8, 2026 | The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The v... |
| CVE-2026-14244 | HIGH | 7.5 | 0.7% | Jul 8, 2026 | The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu... |
| CVE-2026-14158 | HIGH | 8.8 | 0.5% | Jul 8, 2026 | The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including... |
| CVE-2026-60000 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive au... |
| CVE-2026-59999 | HIGH | 7.5 | 0.1% | Jul 8, 2026 | In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not... |
| CVE-2026-55436 | HIGH | 7.4 | 0.3% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and pr... |
| CVE-2026-55429 | HIGH | 8.7 | 0.5% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55428 | HIGH | 8.2 | 0.4% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-55427 | HIGH | 8.3 | 0.5% | Jul 8, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
| CVE-2026-59704 | HIGH | 7.1 | 0.2% | Jul 7, 2026 | Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metada... |
| CVE-2026-55077 | HIGH | 7.2 | 0.6% | Jul 7, 2026 | Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now