2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19343 | HIGH | 7.3 | 0.3% | Aug 9, 2026 | A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown function... |
| CVE-2026-19342 | HIGH | 7.3 | 0.4% | Aug 9, 2026 | A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /i... |
| CVE-2026-19341 | HIGH | 8.8 | 0.4% | Aug 9, 2026 | A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of t... |
| CVE-2026-18464 | HIGH | 7.5 | 0.1% | Aug 9, 2026 | The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is a... |
| CVE-2026-18357 | HIGH | 7.5 | 0.1% | Aug 9, 2026 | The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of... |
| CVE-2026-18032 | HIGH | 7.5 | 0.1% | Aug 9, 2026 | The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthent... |
| CVE-2026-17044 | HIGH | 8.6 | 0.2% | Aug 9, 2026 | The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it ... |
| CVE-2026-17017 | HIGH | 8.1 | 0.2% | Aug 9, 2026 | The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in... |
| CVE-2026-16988 | HIGH | 7.5 | 0.1% | Aug 9, 2026 | The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker dat... |
| CVE-2026-10595 | HIGH | 7.5 | 0.5% | Aug 9, 2026 | A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemen... |
| CVE-2026-17510 | HIGH | 7.5 | 0.2% | Aug 9, 2026 | Crypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero leng... |
| CVE-2026-67620 | HIGH | 7.7 | 0.4% | Aug 8, 2026 | Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity... |
| CVE-2026-42170 | HIGH | 7.8 | 0.2% | Aug 8, 2026 | A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS f... |
| CVE-2026-19263 | HIGH | 7.3 | 1.3% | Aug 8, 2026 | A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted elem... |
| CVE-2026-16948 | HIGH | 8.1 | 0.1% | Aug 8, 2026 | The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exp... |
| CVE-2026-16594 | HIGH | 7.5 | 0.1% | Aug 8, 2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenti... |
| CVE-2026-16589 | HIGH | 7.7 | 0.2% | Aug 8, 2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL sta... |
| CVE-2026-16578 | HIGH | 7.5 | 0.2% | Aug 8, 2026 | The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does n... |
| CVE-2026-16267 | HIGH | 8.1 | 0.2% | Aug 8, 2026 | The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from... |
| CVE-2026-13505 | HIGH | 8.7 | 0.3% | Aug 8, 2026 | In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X ser... |
| CVE-2026-8798 | HIGH | 8.7 | 0.3% | Aug 8, 2026 | In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried ... |
| CVE-2026-52880 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable... |
| CVE-2026-52879 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-mess... |
| CVE-2026-52878 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a... |
| CVE-2026-48120 | HIGH | 8.6 | 0.1% | Aug 7, 2026 | Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now