2026 CVE Vulnerabilities
47,686 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53903 | HIGH | 8.1 | 0.2% | Jul 1, 2026 | MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/tradin... |
| CVE-2026-14181 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | @fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when... |
| CVE-2026-13323 | HIGH | 8.7 | 0.2% | Jul 1, 2026 | In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/h... |
| CVE-2026-13228 | HIGH | 8.8 | — | Jul 1, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca... |
| CVE-2026-12142 | HIGH | 7.2 | — | Jul 1, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2026-50043 | HIGH | 8.6 | 1.1% | Jul 1, 2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-... |
| CVE-2026-12577 | HIGH | 8.7 | 0.3% | Jul 1, 2026 | DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability. |
| CVE-2026-12576 | HIGH | 7.5 | 0.2% | Jul 1, 2026 | DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability. |
| CVE-2026-12575 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | DVP80ES3 with Improper Resource Shutdown or Release vulnerability. |
| CVE-2026-12224 | HIGH | 8.8 | 0.2% | Jul 1, 2026 | The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all ve... |
| CVE-2026-12158 | HIGH | 8.8 | 0.2% | Jul 1, 2026 | The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery ... |
| CVE-2026-10538 | HIGH | 8.9 | 0.2% | Jul 1, 2026 | Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowe... |
| CVE-2026-1239 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access... |
| CVE-2026-14193 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | DVP80ES300T with Improper Validation of Array Index Vulnerability |
| CVE-2026-12579 | HIGH | 7.4 | 0.3% | Jul 1, 2026 | AS228T with Authentication Bypass Vulnerability |
| CVE-2026-11883 | HIGH | 7.2 | 0.2% | Jul 1, 2026 | The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authent... |
| CVE-2026-11823 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date... |
| CVE-2026-11794 | HIGH | 8.1 | 0.1% | Jul 1, 2026 | The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress... |
| CVE-2026-11568 | HIGH | 7.5 | 0.2% | Jul 1, 2026 | The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status... |
| CVE-2026-10750 | HIGH | 8.1 | 0.2% | Jul 1, 2026 | The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after ... |
| CVE-2026-7838 | HIGH | 8.8 | 1.2% | Jul 1, 2026 | UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol failu... |
| CVE-2026-7831 | HIGH | 7.6 | 0.4% | Jul 1, 2026 | UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In v... |
| CVE-2026-7830 | HIGH | 7.4 | 0.2% | Jul 1, 2026 | UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAut... |
| CVE-2026-7829 | HIGH | 7.2 | 0.5% | Jul 1, 2026 | UltraVNC repeater through 1.8.2.2 contains a post-authentication out-of-bounds write in the allow/deny rule parser. In r... |
| CVE-2026-7517 | HIGH | 7.2 | 0.2% | Jul 1, 2026 | The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now