2026 CVE Vulnerabilities
43,031 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16993 | LOW | 3.7 | 0.1% | Aug 5, 2026 | The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage direc... |
| CVE-2026-16746 | LOW | 2.7 | 0.1% | Aug 5, 2026 | The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in... |
| CVE-2026-18852 | LOW | 3.3 | 0.1% | Aug 5, 2026 | A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This imp... |
| CVE-2026-18817 | LOW | 2.2 | 0.2% | Aug 4, 2026 | A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAut... |
| CVE-2026-70483 | LOW | 3.1 | 0.2% | Aug 4, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /a... |
| CVE-2026-16791 | LOW | 3.9 | 0.1% | Aug 4, 2026 | A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could ... |
| CVE-2026-18790 | LOW | 3.3 | — | Aug 4, 2026 | A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMo... |
| CVE-2026-66884 | LOW | 2.1 | — | Aug 4, 2026 | Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback mod... |
| CVE-2026-16070 | LOW | 2.7 | 0.1% | Aug 4, 2026 | The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before upd... |
| CVE-2026-16068 | LOW | 3.5 | 0.2% | Aug 4, 2026 | The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does... |
| CVE-2026-11366 | LOW | 3.7 | 0.1% | Aug 4, 2026 | The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthentica... |
| CVE-2026-68744 | LOW | 3.3 | — | Aug 4, 2026 | A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for... |
| CVE-2026-18739 | LOW | 2.5 | 0.1% | Aug 4, 2026 | A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when... |
| CVE-2026-18569 | LOW | 3.7 | 0.2% | Aug 4, 2026 | A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Bui... |
| CVE-2026-58044 | LOW | 3.7 | — | Aug 4, 2026 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild ou... |
| CVE-2026-11836 | LOW | 1.8 | 0.1% | Aug 4, 2026 | Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in... |
| CVE-2026-46712 | LOW | 2.3 | 0.2% | Aug 3, 2026 | Misskey is an open source, federated social media platform. Versions 2025.3.2 and later, but prior to 2026.5.4, contain ... |
| CVE-2026-18682 | LOW | 3.1 | 0.2% | Aug 3, 2026 | A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api... |
| CVE-2026-63545 | LOW | 2.4 | 0.2% | Aug 3, 2026 | Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They... |
| CVE-2026-18591 | LOW | 2.1 | — | Aug 3, 2026 | A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability i... |
| CVE-2026-16276 | LOW | 2.7 | 0.1% | Aug 3, 2026 | The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns... |
| CVE-2026-16274 | LOW | 2.7 | 0.1% | Aug 3, 2026 | The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action... |
| CVE-2026-15231 | LOW | 2.7 | 0.1% | Aug 3, 2026 | The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to acc... |
| CVE-2026-18581 | LOW | 3.3 | 0.1% | Aug 3, 2026 | A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of th... |
| CVE-2026-15939 | LOW | 2.7 | 0.1% | Aug 2, 2026 | The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now