2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19066 | MEDIUM | 5.3 | 0.3% | Aug 6, 2026 | A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unk... |
| CVE-2026-19065 | MEDIUM | 6.3 | 0.3% | Aug 6, 2026 | A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects... |
| CVE-2026-19064 | MEDIUM | 5.3 | 0.4% | Aug 6, 2026 | A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affe... |
| CVE-2026-19061 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndD... |
| CVE-2026-19060 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulat... |
| CVE-2026-19058 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter ... |
| CVE-2026-19054 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affec... |
| CVE-2026-18487 | MEDIUM | 5.4 | 0.3% | Aug 6, 2026 | A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name s... |
| CVE-2026-16067 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the ... |
| CVE-2026-15256 | MEDIUM | 4.8 | 0.2% | Aug 6, 2026 | The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate ... |
| CVE-2026-15208 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, p... |
| CVE-2026-15152 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment ... |
| CVE-2026-15149 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total ar... |
| CVE-2026-15147 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming paymen... |
| CVE-2026-14936 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the s... |
| CVE-2026-14842 | MEDIUM | 5.3 | 0.3% | Aug 6, 2026 | The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record b... |
| CVE-2026-14831 | MEDIUM | 5.3 | 0.3% | Aug 6, 2026 | The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking durat... |
| CVE-2026-14306 | MEDIUM | 4.3 | 0.2% | Aug 6, 2026 | The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected co... |
| CVE-2026-13342 | MEDIUM | 5.3 | 0.3% | Aug 6, 2026 | The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-base... |
| CVE-2026-12901 | MEDIUM | 5.9 | 0.1% | Aug 6, 2026 | The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, ... |
| CVE-2026-12501 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent... |
| CVE-2026-11361 | MEDIUM | 5.9 | 0.1% | Aug 6, 2026 | The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payme... |
| CVE-2026-68747 | MEDIUM | 6.1 | 0.4% | Aug 6, 2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the ... |
| CVE-2026-66843 | MEDIUM | 6.1 | 0.5% | Aug 6, 2026 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex ... |
| CVE-2026-66829 | MEDIUM | 6.1 | 0.8% | Aug 6, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allow... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now