2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12071 | MEDIUM | 5.3 | 0.3% | Aug 7, 2026 | The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended ... |
| CVE-2026-66493 | MEDIUM | 6.4 | 0.3% | Aug 7, 2026 | Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths... |
| CVE-2026-66492 | MEDIUM | 6.1 | 0.4% | Aug 7, 2026 | Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths... |
| CVE-2026-49008 | MEDIUM | 6.5 | 0.2% | Aug 7, 2026 | By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity... |
| CVE-2026-18938 | MEDIUM | 6.2 | 0.1% | Aug 7, 2026 | A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit a... |
| CVE-2026-49006 | MEDIUM | 5.3 | 0.1% | Aug 7, 2026 | By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmiss... |
| CVE-2026-19079 | MEDIUM | 4.4 | 0.1% | Aug 7, 2026 | A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. W... |
| CVE-2026-16027 | MEDIUM | 5.4 | 0.2% | Aug 7, 2026 | Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Requ... |
| CVE-2026-15239 | MEDIUM | 5.3 | 0.1% | Aug 7, 2026 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache... |
| CVE-2026-15211 | MEDIUM | 5.9 | 0.1% | Aug 7, 2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal ... |
| CVE-2026-15148 | MEDIUM | 5.3 | 0.1% | Aug 7, 2026 | The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates fro... |
| CVE-2026-12261 | MEDIUM | 5.3 | 0.2% | Aug 7, 2026 | A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisonin... |
| CVE-2026-16265 | MEDIUM | 6.5 | 0.1% | Aug 7, 2026 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not r... |
| CVE-2026-16039 | MEDIUM | 6.5 | 0.1% | Aug 7, 2026 | The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, ... |
| CVE-2026-15386 | MEDIUM | 5.4 | 0.2% | Aug 7, 2026 | The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an att... |
| CVE-2026-15359 | MEDIUM | 6.5 | 0.1% | Aug 7, 2026 | The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allow... |
| CVE-2026-15245 | MEDIUM | 5.4 | 0.2% | Aug 7, 2026 | The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript con... |
| CVE-2026-15214 | MEDIUM | 4.3 | 0.1% | Aug 7, 2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription... |
| CVE-2026-15032 | MEDIUM | 6.1 | 0.2% | Aug 7, 2026 | The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an... |
| CVE-2026-14331 | MEDIUM | 6.1 | 0.2% | Aug 7, 2026 | The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a... |
| CVE-2026-12801 | MEDIUM | 6.4 | 0.2% | Aug 7, 2026 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slid... |
| CVE-2026-11907 | MEDIUM | 6.5 | 0.2% | Aug 7, 2026 | The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This ... |
| CVE-2026-45204 | MEDIUM | 5.5 | 0.2% | Aug 7, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kern... |
| CVE-2026-17264 | MEDIUM | 5.3 | 0.3% | Aug 7, 2026 | Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of... |
| CVE-2026-7405 | MEDIUM | 5.5 | 0.1% | Aug 6, 2026 | A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-B... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now