2026 CVE Vulnerabilities
50,911 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61483 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: al... |
| CVE-2026-5651 | MEDIUM | 4.9 | 0.4% | Aug 5, 2026 | The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (a... |
| CVE-2026-5581 | CRITICAL | 9.1 | 0.5% | Aug 5, 2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all ... |
| CVE-2026-5116 | MEDIUM | 4.4 | 0.3% | Aug 5, 2026 | The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ver... |
| CVE-2026-5108 | MEDIUM | 4.4 | 0.2% | Aug 5, 2026 | The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_setti... |
| CVE-2026-59675 | HIGH | 7.5 | — | Aug 5, 2026 | When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a siz... |
| CVE-2026-55998 | MEDIUM | 5.3 | — | Aug 5, 2026 | The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid ... |
| CVE-2026-55997 | HIGH | 8.8 | 0.1% | Aug 5, 2026 | Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These token... |
| CVE-2026-55996 | MEDIUM | 4.3 | 0.1% | Aug 5, 2026 | A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent com... |
| CVE-2026-55747 | MEDIUM | 6.8 | 0.3% | Aug 5, 2026 | The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir... |
| CVE-2026-55739 | HIGH | 8.3 | 0.3% | Aug 5, 2026 | Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability ch... |
| CVE-2026-54418 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, ... |
| CVE-2026-54416 | HIGH | 7.2 | 0.3% | Aug 5, 2026 | Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist i... |
| CVE-2026-4431 | CRITICAL | 9.1 | 0.3% | Aug 5, 2026 | The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2026-18881 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter... |
| CVE-2026-17532 | MEDIUM | 6.1 | 0.3% | Aug 5, 2026 | The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_p... |
| CVE-2026-17505 | MEDIUM | 6.1 | 0.8% | Aug 5, 2026 | The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v... |
| CVE-2026-15281 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the w... |
| CVE-2026-12000 | HIGH | 7.5 | 0.7% | Aug 5, 2026 | The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and... |
| CVE-2026-11977 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to ... |
| CVE-2026-11969 | MEDIUM | 4.9 | 0.3% | Aug 5, 2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Paramete... |
| CVE-2026-11920 | MEDIUM | 4.9 | 0.3% | Aug 5, 2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL ... |
| CVE-2026-11454 | MEDIUM | 6.5 | 0.4% | Aug 5, 2026 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object... |
| CVE-2026-71201 | MEDIUM | 5 | 0.2% | Aug 5, 2026 | In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assign... |
| CVE-2026-70375 | HIGH | 8.8 | 1.0% | Aug 5, 2026 | HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDe... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now