2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14862 | LOW | 3.7 | 0.2% | Jul 31, 2026 | The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downlo... |
| CVE-2026-14849 | LOW | 3.7 | 0.2% | Jul 31, 2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it... |
| CVE-2026-13393 | LOW | 3.5 | 0.1% | Jul 31, 2026 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item... |
| CVE-2026-58039 | LOW | 3.3 | 0.2% | Jul 31, 2026 | A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-wr... |
| CVE-2026-41709 | LOW | 2.7 | — | Jul 30, 2026 | VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform... |
| CVE-2026-59326 | LOW | 3.3 | 0.1% | Jul 30, 2026 | The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment vari... |
| CVE-2026-15054 | LOW | 3.7 | 0.2% | Jul 30, 2026 | The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submiss... |
| CVE-2026-14222 | LOW | 3.8 | 0.2% | Jul 30, 2026 | The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its conne... |
| CVE-2026-14221 | LOW | 3.8 | 0.2% | Jul 30, 2026 | The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-mana... |
| CVE-2026-14188 | LOW | 2.7 | 0.2% | Jul 30, 2026 | The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of... |
| CVE-2026-18011 | LOW | 2.4 | 0.1% | Jul 30, 2026 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker t... |
| CVE-2026-18000 | LOW | 3.1 | 0.1% | Jul 30, 2026 | Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who ... |
| CVE-2026-17997 | LOW | 3.1 | 0.1% | Jul 30, 2026 | Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had comp... |
| CVE-2026-17984 | LOW | 3.3 | 0.1% | Jul 30, 2026 | Inappropriate implementation in Browser in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to l... |
| CVE-2026-17980 | LOW | 3.1 | 0.2% | Jul 30, 2026 | Inappropriate implementation in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who conv... |
| CVE-2026-17957 | LOW | 3.1 | 0.1% | Jul 30, 2026 | Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromis... |
| CVE-2026-17902 | LOW | 3.5 | 0.2% | Jul 30, 2026 | Inappropriate implementation in Editing in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to le... |
| CVE-2026-17860 | LOW | 3.3 | 0.1% | Jul 30, 2026 | Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a local ... |
| CVE-2026-17826 | LOW | 3.1 | 0.1% | Jul 30, 2026 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker ... |
| CVE-2026-17766 | LOW | 3.3 | 0.1% | Jul 30, 2026 | Insufficient validation of untrusted input in Clipboard in Google Chrome on Android prior to 151.0.7922.72 allowed a loc... |
| CVE-2026-17732 | LOW | 3.1 | 0.1% | Jul 30, 2026 | Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-orig... |
| CVE-2026-17720 | LOW | 3.1 | 0.1% | Jul 30, 2026 | Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had c... |
| CVE-2026-17715 | LOW | 3.1 | 0.2% | Jul 30, 2026 | Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convince... |
| CVE-2026-17702 | LOW | 3.1 | 0.2% | Jul 30, 2026 | Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromis... |
| CVE-2026-62995 | LOW | 2.3 | 0.1% | Jul 29, 2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now