2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-65541 | HIGH | 7.3 | 0.2% | Aug 6, 2026 | Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions. |
| CVE-2026-65523 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0... |
| CVE-2026-65517 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions. |
| CVE-2026-65515 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. |
| CVE-2026-65513 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. |
| CVE-2026-65509 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. |
| CVE-2026-65504 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions. |
| CVE-2026-61982 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. |
| CVE-2026-61964 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. |
| CVE-2026-61963 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions. |
| CVE-2026-61961 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. |
| CVE-2026-34502 | HIGH | 7.5 | 0.4% | Aug 6, 2026 | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache ... |
| CVE-2026-34501 | HIGH | 7.5 | 0.4% | Aug 6, 2026 | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Por... |
| CVE-2026-28177 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. |
| CVE-2026-28172 | HIGH | 7.1 | 0.1% | Aug 6, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions. |
| CVE-2026-28143 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. |
| CVE-2026-28141 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions. |
| CVE-2026-28140 | HIGH | 7.5 | 0.2% | Aug 6, 2026 | Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. |
| CVE-2026-28111 | HIGH | 8.8 | 0.3% | Aug 6, 2026 | Contributor Privilege Escalation in Forminator <= 1.56.0 versions. |
| CVE-2026-28082 | HIGH | 7.1 | 0.2% | Aug 6, 2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. |
| CVE-2026-16731 | HIGH | 8.3 | — | Aug 6, 2026 | OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authe... |
| CVE-2026-16315 | HIGH | 8.7 | — | Aug 6, 2026 | OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authe... |
| CVE-2026-66733 | HIGH | 8.7 | — | Aug 6, 2026 | Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enque... |
| CVE-2026-66732 | HIGH | 8.3 | — | Aug 6, 2026 | Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager whe... |
| CVE-2026-65551 | HIGH | 7.5 | 0.2% | Aug 6, 2026 | Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Securit... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now