2026 CVE Vulnerabilities
48,546 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-65509 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. |
| CVE-2026-65508 | CRITICAL | 9.3 | 0.3% | Aug 6, 2026 | Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions. |
| CVE-2026-65507 | CRITICAL | 9.8 | 0.3% | Aug 6, 2026 | Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. |
| CVE-2026-65504 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions. |
| CVE-2026-65502 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions. |
| CVE-2026-61982 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. |
| CVE-2026-61964 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. |
| CVE-2026-61963 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions. |
| CVE-2026-61961 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. |
| CVE-2026-61959 | MEDIUM | 6.5 | 0.2% | Aug 6, 2026 | Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions. |
| CVE-2026-54489 | CRITICAL | 9.8 | 0.4% | Aug 6, 2026 | Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Informati... |
| CVE-2026-53976 | CRITICAL | 9.3 | — | Aug 6, 2026 | OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and... |
| CVE-2026-53975 | CRITICAL | 9.8 | — | Aug 6, 2026 | OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execu... |
| CVE-2026-34502 | HIGH | 7.5 | 0.4% | Aug 6, 2026 | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache ... |
| CVE-2026-34501 | HIGH | 7.5 | 0.4% | Aug 6, 2026 | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Por... |
| CVE-2026-34191 | CRITICAL | 9.1 | 0.3% | Aug 6, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Ru... |
| CVE-2026-32548 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions. |
| CVE-2026-32469 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions. |
| CVE-2026-32327 | CRITICAL | 9.1 | 0.3% | Aug 6, 2026 | A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses ... |
| CVE-2026-28183 | — | — | — | Aug 6, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-28180 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions. |
| CVE-2026-28179 | MEDIUM | 5.9 | 0.2% | Aug 6, 2026 | Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions. |
| CVE-2026-28178 | MEDIUM | 6.5 | 0.2% | Aug 6, 2026 | Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. |
| CVE-2026-28177 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. |
| CVE-2026-28172 | HIGH | 7.1 | 0.1% | Aug 6, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now