2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18967 | HIGH | 8.1 | 0.1% | Aug 6, 2026 | A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured a... |
| CVE-2026-18510 | HIGH | 7.2 | 0.2% | Aug 6, 2026 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2026-18050 | HIGH | 7.5 | 0.1% | Aug 6, 2026 | The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves tem... |
| CVE-2026-16734 | HIGH | 7.5 | 0.1% | Aug 6, 2026 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe p... |
| CVE-2026-16268 | HIGH | 8.2 | 0.1% | Aug 6, 2026 | The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetchi... |
| CVE-2026-14829 | HIGH | 8.2 | 0.1% | Aug 6, 2026 | The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not pr... |
| CVE-2026-13154 | HIGH | 7.5 | 0.1% | Aug 6, 2026 | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is pub... |
| CVE-2026-13153 | HIGH | 7.5 | 0.1% | Aug 6, 2026 | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes ... |
| CVE-2026-19000 | HIGH | 7.3 | 0.3% | Aug 6, 2026 | A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/... |
| CVE-2026-15459 | HIGH | 8.1 | 0.5% | Aug 6, 2026 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,... |
| CVE-2026-18325 | HIGH | 7.2 | 0.3% | Aug 6, 2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2026-16636 | HIGH | 7.2 | 0.3% | Aug 6, 2026 | The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for Wo... |
| CVE-2026-15991 | HIGH | 8.8 | 0.6% | Aug 6, 2026 | The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation ... |
| CVE-2026-18991 | HIGH | 7.3 | 0.5% | Aug 6, 2026 | A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file c... |
| CVE-2026-18990 | HIGH | 7.3 | 0.4% | Aug 6, 2026 | A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts o... |
| CVE-2026-18973 | HIGH | 7.3 | 0.3% | Aug 6, 2026 | A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitiz... |
| CVE-2026-67872 | HIGH | 7.5 | — | Aug 6, 2026 | An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queu... |
| CVE-2026-67871 | HIGH | 7.5 | — | Aug 6, 2026 | Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddN... |
| CVE-2026-67869 | HIGH | 7.5 | — | Aug 6, 2026 | Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_... |
| CVE-2026-18970 | HIGH | 7.3 | 0.3% | Aug 6, 2026 | A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected elemen... |
| CVE-2026-18969 | HIGH | 7.3 | 0.3% | Aug 6, 2026 | A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is ... |
| CVE-2026-67867 | HIGH | 7.5 | — | Aug 5, 2026 | Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alar... |
| CVE-2026-67866 | HIGH | 7.5 | — | Aug 5, 2026 | Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Lock... |
| CVE-2026-67863 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when ... |
| CVE-2026-19024 | HIGH | 8.2 | 0.1% | Aug 5, 2026 | NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a d... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now