2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7529 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and... |
| CVE-2026-67623 | HIGH | 8.8 | — | Aug 5, 2026 | Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers to execute arbitrary com... |
| CVE-2026-17506 | HIGH | 7.2 | 0.2% | Aug 5, 2026 | The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tr... |
| CVE-2026-15979 | HIGH | 8.1 | 0.8% | Aug 5, 2026 | The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Del... |
| CVE-2026-71294 | HIGH | 7.6 | 0.2% | Aug 5, 2026 | Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. ... |
| CVE-2026-71292 | HIGH | 7.2 | 0.3% | Aug 5, 2026 | Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists th... |
| CVE-2026-71291 | HIGH | 8.8 | 0.5% | Aug 5, 2026 | Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registe... |
| CVE-2026-71288 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | Koha's guided report builder (reports/guided_reports.pl) reads the CGI parameter and, for each value, a dynamically-name... |
| CVE-2026-71287 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because ... |
| CVE-2026-71285 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo ... |
| CVE-2026-71284 | HIGH | 7.2 | 0.9% | Aug 5, 2026 | Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the fir... |
| CVE-2026-71281 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src... |
| CVE-2026-71280 | HIGH | 8.5 | 0.2% | Aug 5, 2026 | go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Clien... |
| CVE-2026-71279 | HIGH | 8 | 0.4% | Aug 5, 2026 | Zigbee2MQTT's ExternalJSExtension.getFilePath (lib/extension/externalJS.ts) joins a parameter received via an MQTT messa... |
| CVE-2026-71276 | HIGH | 7.1 | 0.2% | Aug 5, 2026 | Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transpor... |
| CVE-2026-71274 | HIGH | 8.5 | 0.2% | Aug 5, 2026 | OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel co... |
| CVE-2026-71272 | HIGH | 8.5 | 0.2% | Aug 5, 2026 | Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.Defa... |
| CVE-2026-71271 | HIGH | 8.5 | 0.3% | Aug 5, 2026 | Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDR... |
| CVE-2026-71270 | HIGH | 8.6 | 0.3% | Aug 5, 2026 | Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanit... |
| CVE-2026-71269 | HIGH | 7.2 | 0.6% | Aug 5, 2026 | Node-RED's local-filesystem library storage module (getLibraryEntry and saveLibraryEntry in packages/node_modules/@node-... |
| CVE-2026-71266 | HIGH | 7.8 | 0.1% | Aug 5, 2026 | tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a f... |
| CVE-2026-71265 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data ... |
| CVE-2026-71264 | HIGH | 8.2 | 0.2% | Aug 5, 2026 | WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike ... |
| CVE-2026-71261 | HIGH | 7.8 | 0.1% | Aug 5, 2026 | dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. I... |
| CVE-2026-71259 | HIGH | 8.6 | 0.1% | Aug 5, 2026 | ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now