2026 CVE Vulnerabilities
50,998 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66401 | LOW | 2.4 | 0.2% | Aug 1, 2026 | FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fail... |
| CVE-2026-2411 | MEDIUM | 6.5 | 0.1% | Aug 1, 2026 | Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose... |
| CVE-2026-10773 | MEDIUM | 5.4 | 0.2% | Aug 1, 2026 | The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const c... |
| CVE-2026-10772 | — | — | — | Aug 1, 2026 | Rejected reason: ** DUPLICATE ** This CVE Record has been rejected by the Zephyr Project CNA. CVE-2026-10772 was assigne... |
| CVE-2026-18536 | HIGH | 7.5 | 0.2% | Aug 1, 2026 | Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource:... |
| CVE-2026-6453 | MEDIUM | 6.5 | 0.3% | Aug 1, 2026 | The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. Thi... |
| CVE-2026-18435 | MEDIUM | 6.4 | 0.2% | Aug 1, 2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2026-18344 | MEDIUM | 6.1 | 0.2% | Aug 1, 2026 | The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' par... |
| CVE-2026-18062 | MEDIUM | 6.4 | 0.2% | Aug 1, 2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2026-18059 | MEDIUM | 5.3 | 0.3% | Aug 1, 2026 | The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exp... |
| CVE-2026-17605 | MEDIUM | 6.6 | 0.7% | Aug 1, 2026 | The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Incl... |
| CVE-2026-17580 | MEDIUM | 6.5 | 0.3% | Aug 1, 2026 | The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elem... |
| CVE-2026-17571 | MEDIUM | 6.1 | 0.2% | Aug 1, 2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
| CVE-2026-17555 | MEDIUM | 4.9 | 0.3% | Aug 1, 2026 | The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in vers... |
| CVE-2026-16685 | MEDIUM | 6.4 | 0.2% | Aug 1, 2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in... |
| CVE-2026-16684 | MEDIUM | 6.4 | 0.2% | Aug 1, 2026 | The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact... |
| CVE-2026-16635 | HIGH | 8.8 | 0.3% | Aug 1, 2026 | The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0... |
| CVE-2026-16614 | MEDIUM | 4.9 | 0.3% | Aug 1, 2026 | The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL ... |
| CVE-2026-16144 | HIGH | 8.1 | 0.7% | Aug 1, 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all... |
| CVE-2026-16091 | MEDIUM | 6.4 | 0.2% | Aug 1, 2026 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ... |
| CVE-2026-16090 | MEDIUM | 6.4 | 0.2% | Aug 1, 2026 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ... |
| CVE-2026-16087 | MEDIUM | 6.5 | 0.3% | Aug 1, 2026 | The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injec... |
| CVE-2026-15964 | CRITICAL | 9.8 | 0.5% | Aug 1, 2026 | The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password rese... |
| CVE-2026-15951 | MEDIUM | 4.9 | 0.3% | Aug 1, 2026 | The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and... |
| CVE-2026-15950 | MEDIUM | 6.4 | 0.2% | Aug 1, 2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now