2026 CVE Vulnerabilities
48,281 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9710 | HIGH | 7.7 | 0.2% | Jun 24, 2026 | The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handl... |
| CVE-2026-9709 | HIGH | 7.7 | 0.2% | Jun 24, 2026 | The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing... |
| CVE-2026-9643 | HIGH | 7.2 | 0.2% | Jun 24, 2026 | The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI se... |
| CVE-2026-9179 | HIGH | 7.5 | 0.4% | Jun 24, 2026 | The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/... |
| CVE-2026-9178 | HIGH | 7.5 | 0.3% | Jun 24, 2026 | The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, ... |
| CVE-2026-8705 | HIGH | 7.5 | 0.5% | Jun 24, 2026 | The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of th... |
| CVE-2026-4297 | HIGH | 8.8 | 0.5% | Jun 24, 2026 | The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and... |
| CVE-2026-13006 | HIGH | 7 | 0.1% | Jun 24, 2026 | ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.3... |
| CVE-2026-12100 | HIGH | 7.2 | 0.3% | Jun 24, 2026 | The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ... |
| CVE-2026-12095 | HIGH | 7.2 | 0.3% | Jun 24, 2026 | The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ... |
| CVE-2026-10749 | HIGH | 7.2 | 0.3% | Jun 24, 2026 | The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, stor... |
| CVE-2026-10735 | HIGH | 7.5 | 0.4% | Jun 24, 2026 | Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, P... |
| CVE-2026-10092 | HIGH | 7.2 | 0.3% | Jun 24, 2026 | The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortc... |
| CVE-2026-10091 | HIGH | 7.2 | 0.3% | Jun 24, 2026 | The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' sh... |
| CVE-2026-3652 | HIGH | 7.2 | 0.2% | Jun 24, 2026 | The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save... |
| CVE-2026-12681 | HIGH | 8.9 | 0.2% | Jun 24, 2026 | Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSig... |
| CVE-2026-54639 | HIGH | 8.8 | 0.1% | Jun 24, 2026 | Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in... |
| CVE-2026-7574 | HIGH | 8.7 | 0.1% | Jun 24, 2026 | Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1... |
| CVE-2026-5818 | HIGH | 7.2 | 0.2% | Jun 24, 2026 | Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) al... |
| CVE-2026-56785 | HIGH | 8.4 | 0.2% | Jun 23, 2026 | FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email f... |
| CVE-2026-11972 | HIGH | 8.2 | 0.4% | Jun 23, 2026 | When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly h... |
| CVE-2026-54513 | HIGH | 8.1 | 0.7% | Jun 23, 2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From... |
| CVE-2026-54512 | HIGH | 8.1 | 0.6% | Jun 23, 2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From... |
| CVE-2026-50193 | HIGH | 7.5 | 0.5% | Jun 23, 2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From... |
| CVE-2026-47387 | HIGH | 8.4 | 0.2% | Jun 23, 2026 | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the shared form-view submit handler (pack... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now