2026 CVE Vulnerabilities
48,546 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28169 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions. |
| CVE-2026-28146 | MEDIUM | 6.5 | 0.3% | Aug 6, 2026 | Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 vers... |
| CVE-2026-28143 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. |
| CVE-2026-28141 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions. |
| CVE-2026-28140 | HIGH | 7.5 | 0.2% | Aug 6, 2026 | Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. |
| CVE-2026-28139 | CRITICAL | 9.8 | 0.4% | Aug 6, 2026 | Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. |
| CVE-2026-28111 | HIGH | 8.8 | 0.3% | Aug 6, 2026 | Contributor Privilege Escalation in Forminator <= 1.56.0 versions. |
| CVE-2026-28082 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. |
| CVE-2026-28005 | CRITICAL | 9.8 | 0.3% | Aug 6, 2026 | Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. |
| CVE-2026-25403 | MEDIUM | 6.5 | 0.2% | Aug 6, 2026 | Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. |
| CVE-2026-19045 | MEDIUM | 5.3 | 0.6% | Aug 6, 2026 | A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog... |
| CVE-2026-19044 | MEDIUM | 5.3 | 0.7% | Aug 6, 2026 | A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of... |
| CVE-2026-15246 | MEDIUM | 4.3 | — | Aug 6, 2026 | The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, no... |
| CVE-2026-64993 | CRITICAL | 9.1 | 0.1% | Aug 6, 2026 | Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remo... |
| CVE-2026-5134 | CRITICAL | 9.8 | — | Aug 6, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Info... |
| CVE-2026-19041 | MEDIUM | 6.3 | 1.7% | Aug 6, 2026 | A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageSe... |
| CVE-2026-19040 | MEDIUM | 6.3 | 0.4% | Aug 6, 2026 | A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/... |
| CVE-2026-18501 | MEDIUM | 6.4 | 0.2% | Aug 6, 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre... |
| CVE-2026-16731 | HIGH | 8.3 | — | Aug 6, 2026 | OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authe... |
| CVE-2026-16316 | MEDIUM | 4.3 | — | Aug 6, 2026 | OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame... |
| CVE-2026-16315 | HIGH | 8.7 | — | Aug 6, 2026 | OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authe... |
| CVE-2026-12605 | CRITICAL | 9.6 | 0.2% | Aug 6, 2026 | In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfrestt... |
| CVE-2026-70556 | MEDIUM | 5.1 | 0.1% | Aug 6, 2026 | Hubzilla versions prior to 11.4 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint h... |
| CVE-2026-66733 | HIGH | 8.7 | — | Aug 6, 2026 | Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enque... |
| CVE-2026-66732 | HIGH | 8.3 | — | Aug 6, 2026 | Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager whe... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now