2026 CVE Vulnerabilities
50,970 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18755 | HIGH | 7.3 | — | Aug 4, 2026 | A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search di... |
| CVE-2026-18754 | CRITICAL | 9.1 | — | Aug 4, 2026 | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS terminatio... |
| CVE-2026-18753 | CRITICAL | 9.1 | — | Aug 4, 2026 | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS terminatio... |
| CVE-2026-64565 | — | — | 0.2% | Aug 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix heap-buffer-overflow in ims_pc... |
| CVE-2026-64564 | CRITICAL | 9.8 | 0.5% | Aug 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-... |
| CVE-2026-64563 | HIGH | 7.8 | 0.1% | Aug 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart r... |
| CVE-2026-64562 | HIGH | 8.8 | 0.1% | Aug 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR fr... |
| CVE-2026-64561 | HIGH | 8.8 | 0.3% | Aug 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* m... |
| CVE-2026-16623 | HIGH | 8 | 0.2% | Aug 4, 2026 | The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a g... |
| CVE-2026-16618 | CRITICAL | 9.8 | 0.5% | Aug 4, 2026 | The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file conten... |
| CVE-2026-16548 | MEDIUM | 6.5 | 0.4% | Aug 4, 2026 | The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin be... |
| CVE-2026-16547 | MEDIUM | 5.9 | 0.3% | Aug 4, 2026 | The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log en... |
| CVE-2026-16546 | MEDIUM | 4.3 | 0.2% | Aug 4, 2026 | The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJA... |
| CVE-2026-16536 | MEDIUM | 5.3 | 0.2% | Aug 4, 2026 | The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL bef... |
| CVE-2026-16296 | MEDIUM | 4.7 | 0.2% | Aug 4, 2026 | The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect... |
| CVE-2026-16295 | MEDIUM | 4.3 | 0.2% | Aug 4, 2026 | The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch p... |
| CVE-2026-16293 | MEDIUM | 6.8 | 0.2% | Aug 4, 2026 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Po... |
| CVE-2026-16070 | LOW | 2.7 | 0.2% | Aug 4, 2026 | The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before upd... |
| CVE-2026-16069 | MEDIUM | 6.8 | 0.2% | Aug 4, 2026 | The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted t... |
| CVE-2026-16068 | LOW | 3.5 | 0.1% | Aug 4, 2026 | The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does... |
| CVE-2026-16056 | MEDIUM | 4.3 | 0.2% | Aug 4, 2026 | The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handler... |
| CVE-2026-16035 | MEDIUM | 4.3 | 0.2% | Aug 4, 2026 | The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP ... |
| CVE-2026-15958 | CRITICAL | 9.3 | 0.2% | Aug 4, 2026 | The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its ... |
| CVE-2026-15233 | MEDIUM | 4.8 | 0.1% | Aug 4, 2026 | The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML at... |
| CVE-2026-14939 | MEDIUM | 6.8 | 0.2% | Aug 4, 2026 | The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetchi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now