2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16583 | MEDIUM | 6.1 | 0.2% | Aug 5, 2026 | The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8... |
| CVE-2026-8790 | MEDIUM | 6.1 | 0.2% | Aug 5, 2026 | The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST paramete... |
| CVE-2026-7753 | MEDIUM | 6.5 | 0.4% | Aug 5, 2026 | The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing... |
| CVE-2026-71192 | MEDIUM | 6 | — | Aug 5, 2026 | In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-C... |
| CVE-2026-71191 | MEDIUM | 6 | 0.3% | Aug 5, 2026 | In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the Si... |
| CVE-2026-66344 | MEDIUM | 6.7 | — | Aug 5, 2026 | NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerabi... |
| CVE-2026-5062 | MEDIUM | 4.9 | 0.3% | Aug 5, 2026 | The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPre... |
| CVE-2026-18903 | MEDIUM | 4.3 | 0.4% | Aug 5, 2026 | A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects so... |
| CVE-2026-15941 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches f... |
| CVE-2026-11421 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Inje... |
| CVE-2026-18896 | MEDIUM | 6.3 | 0.2% | Aug 5, 2026 | A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown fun... |
| CVE-2026-18856 | MEDIUM | 4.7 | 0.2% | Aug 5, 2026 | A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFil... |
| CVE-2026-45705 | MEDIUM | 5.3 | — | Aug 5, 2026 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the fin... |
| CVE-2026-18853 | MEDIUM | 5.3 | 0.2% | Aug 5, 2026 | A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the fu... |
| CVE-2026-18103 | MEDIUM | 4.9 | 0.4% | Aug 5, 2026 | A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Program... |
| CVE-2026-18819 | MEDIUM | 4.3 | 0.2% | Aug 4, 2026 | A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vul... |
| CVE-2026-18818 | MEDIUM | 6.3 | 0.2% | Aug 4, 2026 | A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView o... |
| CVE-2026-70620 | MEDIUM | 6.8 | 0.3% | Aug 4, 2026 | Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attacke... |
| CVE-2026-70594 | MEDIUM | 6.7 | 0.2% | Aug 4, 2026 | Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions ... |
| CVE-2026-70593 | MEDIUM | 6.6 | 0.3% | Aug 4, 2026 | Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff... |
| CVE-2026-70592 | MEDIUM | 5.5 | 0.3% | Aug 4, 2026 | Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overw... |
| CVE-2026-70591 | MEDIUM | 4.1 | 0.2% | Aug 4, 2026 | Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin ima... |
| CVE-2026-70590 | MEDIUM | 4.8 | 0.2% | Aug 4, 2026 | Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed password... |
| CVE-2026-70589 | MEDIUM | 4.8 | 0.2% | Aug 4, 2026 | Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to rede... |
| CVE-2026-52370 | MEDIUM | 6.1 | 0.2% | Aug 4, 2026 | A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now