2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17532 | MEDIUM | 6.1 | 0.3% | Aug 5, 2026 | The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_p... |
| CVE-2026-17505 | MEDIUM | 6.1 | 0.8% | Aug 5, 2026 | The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v... |
| CVE-2026-15281 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the w... |
| CVE-2026-11977 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to ... |
| CVE-2026-11969 | MEDIUM | 4.9 | 0.3% | Aug 5, 2026 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Paramete... |
| CVE-2026-11920 | MEDIUM | 4.9 | 0.3% | Aug 5, 2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL ... |
| CVE-2026-11454 | MEDIUM | 6.5 | 0.4% | Aug 5, 2026 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object... |
| CVE-2026-71201 | MEDIUM | 5 | 0.2% | Aug 5, 2026 | In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assign... |
| CVE-2026-68080 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated atta... |
| CVE-2026-68078 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att... |
| CVE-2026-68077 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to ... |
| CVE-2026-68075 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service... |
| CVE-2026-67591 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service... |
| CVE-2026-67555 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att... |
| CVE-2026-67554 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to ... |
| CVE-2026-67553 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service... |
| CVE-2026-66277 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att... |
| CVE-2026-66276 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to ... |
| CVE-2026-66275 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service... |
| CVE-2026-49004 | MEDIUM | 6.5 | 0.7% | Aug 5, 2026 | The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabi... |
| CVE-2026-17515 | MEDIUM | 4.3 | 0.1% | Aug 5, 2026 | The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisatio... |
| CVE-2026-16981 | MEDIUM | 5.3 | 0.1% | Aug 5, 2026 | The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capa... |
| CVE-2026-16968 | MEDIUM | 6.5 | 0.1% | Aug 5, 2026 | The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users... |
| CVE-2026-16942 | MEDIUM | 5.4 | 0.2% | Aug 5, 2026 | The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page hand... |
| CVE-2026-16613 | MEDIUM | 4.3 | 0.1% | Aug 5, 2026 | The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now