2026 CVE Vulnerabilities
48,516 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52696 | HIGH | 7.5 | 0.2% | Jun 17, 2026 | Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions. |
| CVE-2026-49778 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions. |
| CVE-2026-49113 | HIGH | 8.5 | 0.4% | Jun 17, 2026 | Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions. |
| CVE-2026-49081 | HIGH | 8.2 | 0.3% | Jun 17, 2026 | Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions. |
| CVE-2026-49074 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions. |
| CVE-2026-49073 | HIGH | 8.5 | 0.2% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist ... |
| CVE-2026-49057 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions. |
| CVE-2026-48967 | HIGH | 8.5 | 0.3% | Jun 17, 2026 | Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions. |
| CVE-2026-48929 | HIGH | 7.5 | 0.7% | Jun 17, 2026 | Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthent... |
| CVE-2026-48869 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions. |
| CVE-2026-48788 | HIGH | 8.2 | 0.3% | Jun 17, 2026 | Remark42 is a self-hosted comment engine for blogs, articles, or any other place where readers can add comments. Version... |
| CVE-2026-48779 | HIGH | 7.5 | 0.8% | Jun 17, 2026 | ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, f... |
| CVE-2026-42629 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions. |
| CVE-2026-42385 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions. |
| CVE-2026-41557 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions. |
| CVE-2026-40768 | HIGH | 7.3 | 0.3% | Jun 17, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions. |
| CVE-2026-40765 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions. |
| CVE-2026-40761 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions. |
| CVE-2026-40760 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Behold <= 1.5 versions. |
| CVE-2026-40759 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Esmée <= 1.4 versions. |
| CVE-2026-40758 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions. |
| CVE-2026-40755 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in TechLink <= 1.3 versions. |
| CVE-2026-40754 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Roisin <= 1.4 versions. |
| CVE-2026-40753 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions. |
| CVE-2026-40751 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now