2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16274 | LOW | 2.7 | 0.2% | Aug 3, 2026 | The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action... |
| CVE-2026-15231 | LOW | 2.7 | 0.2% | Aug 3, 2026 | The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to acc... |
| CVE-2026-18581 | LOW | 3.3 | 0.1% | Aug 3, 2026 | A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of th... |
| CVE-2026-15939 | LOW | 2.7 | 0.2% | Aug 2, 2026 | The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST ... |
| CVE-2026-67334 | LOW | 3.8 | 0.2% | Aug 1, 2026 | better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endp... |
| CVE-2026-67319 | LOW | 3.7 | 0.3% | Aug 1, 2026 | axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the... |
| CVE-2026-66401 | LOW | 2.1 | 0.1% | Aug 1, 2026 | FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fail... |
| CVE-2026-14823 | LOW | 2.2 | 0.1% | Aug 1, 2026 | The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of it... |
| CVE-2026-14214 | LOW | 2.7 | 0.2% | Aug 1, 2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be wr... |
| CVE-2026-14197 | LOW | 3.8 | 0.2% | Aug 1, 2026 | The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket... |
| CVE-2026-14195 | LOW | 2.7 | 0.2% | Aug 1, 2026 | The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning p... |
| CVE-2026-11882 | LOW | 3.7 | 0.2% | Aug 1, 2026 | The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes... |
| CVE-2026-10827 | LOW | 3.5 | 0.1% | Aug 1, 2026 | The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before usi... |
| CVE-2026-54787 | LOW | 3.1 | 0.1% | Jul 31, 2026 | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle s... |
| CVE-2026-55825 | LOW | 3.1 | 0.2% | Jul 31, 2026 | Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can ... |
| CVE-2026-57232 | LOW | 3.1 | 0.2% | Jul 31, 2026 | Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end mod... |
| CVE-2026-55824 | LOW | 2.6 | 0.2% | Jul 31, 2026 | Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth cre... |
| CVE-2026-25552 | LOW | 3.7 | 0.2% | Jul 31, 2026 | Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rat... |
| CVE-2026-56569 | LOW | 3.3 | 0.1% | Jul 31, 2026 | HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal config... |
| CVE-2026-56567 | LOW | 3.3 | 0.1% | Jul 31, 2026 | HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of intern... |
| CVE-2026-65636 | LOW | 2.1 | 0.1% | Jul 31, 2026 | Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ymlr (Elixir.Ymlr module) allows attackers to inj... |
| CVE-2026-18206 | LOW | 3.7 | 0.2% | Jul 31, 2026 | A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services.... |
| CVE-2026-15381 | LOW | 3.7 | 0.2% | Jul 31, 2026 | The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a S... |
| CVE-2026-14927 | LOW | 3.7 | 0.2% | Jul 31, 2026 | The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership che... |
| CVE-2026-14862 | LOW | 3.7 | 0.2% | Jul 31, 2026 | The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downlo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now