2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32469 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions. |
| CVE-2026-28180 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions. |
| CVE-2026-28179 | MEDIUM | 5.9 | 0.2% | Aug 6, 2026 | Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions. |
| CVE-2026-28178 | MEDIUM | 6.5 | 0.2% | Aug 6, 2026 | Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. |
| CVE-2026-28169 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions. |
| CVE-2026-28146 | MEDIUM | 6.5 | 0.3% | Aug 6, 2026 | Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 vers... |
| CVE-2026-25403 | MEDIUM | 6.5 | 0.2% | Aug 6, 2026 | Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. |
| CVE-2026-19045 | MEDIUM | 5.3 | 0.6% | Aug 6, 2026 | A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog... |
| CVE-2026-19044 | MEDIUM | 5.3 | 0.7% | Aug 6, 2026 | A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of... |
| CVE-2026-15246 | MEDIUM | 4.3 | — | Aug 6, 2026 | The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, no... |
| CVE-2026-19041 | MEDIUM | 6.3 | 1.7% | Aug 6, 2026 | A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageSe... |
| CVE-2026-19040 | MEDIUM | 6.3 | 0.4% | Aug 6, 2026 | A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/... |
| CVE-2026-18501 | MEDIUM | 6.4 | 0.2% | Aug 6, 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre... |
| CVE-2026-16316 | MEDIUM | 4.3 | — | Aug 6, 2026 | OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame... |
| CVE-2026-70556 | MEDIUM | 5.1 | — | Aug 6, 2026 | Hubzilla 11.2.1 contains a cross-site request forgery vulnerability in the OAuth2 /authorize endpoint handled by Zotlabs... |
| CVE-2026-19039 | MEDIUM | 5.3 | 0.8% | Aug 6, 2026 | A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted ... |
| CVE-2026-19038 | MEDIUM | 6.3 | 0.5% | Aug 6, 2026 | A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function sc... |
| CVE-2026-19037 | MEDIUM | 4.3 | 0.4% | Aug 6, 2026 | A weakness has been identified in WonderTrader up to 0.9.9. This vulnerability affects the function MatchEngine::update_... |
| CVE-2026-0673 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to... |
| CVE-2026-8166 | MEDIUM | 5.4 | — | Aug 6, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Indu... |
| CVE-2026-5391 | MEDIUM | 6.4 | 0.2% | Aug 6, 2026 | The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute ... |
| CVE-2026-5158 | MEDIUM | 6.4 | 0.2% | Aug 6, 2026 | The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored C... |
| CVE-2026-11983 | MEDIUM | 5.3 | 0.3% | Aug 6, 2026 | The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up... |
| CVE-2026-55980 | MEDIUM | 5.5 | — | Aug 6, 2026 | A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leadin... |
| CVE-2026-55979 | MEDIUM | 5.2 | — | Aug 6, 2026 | An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke Ca... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now