2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14194 | MEDIUM | 6.5 | — | Aug 4, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Infor... |
| CVE-2026-14192 | MEDIUM | 5.4 | — | Aug 4, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and... |
| CVE-2026-16548 | MEDIUM | 6.5 | 0.2% | Aug 4, 2026 | The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin be... |
| CVE-2026-16547 | MEDIUM | 5.9 | 0.2% | Aug 4, 2026 | The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log en... |
| CVE-2026-16546 | MEDIUM | 4.3 | 0.1% | Aug 4, 2026 | The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJA... |
| CVE-2026-16536 | MEDIUM | 5.3 | 0.1% | Aug 4, 2026 | The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL bef... |
| CVE-2026-16296 | MEDIUM | 4.7 | 0.1% | Aug 4, 2026 | The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect... |
| CVE-2026-16295 | MEDIUM | 4.3 | 0.1% | Aug 4, 2026 | The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch p... |
| CVE-2026-16293 | MEDIUM | 6.8 | 0.2% | Aug 4, 2026 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Po... |
| CVE-2026-16069 | MEDIUM | 6.8 | 0.2% | Aug 4, 2026 | The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted t... |
| CVE-2026-16056 | MEDIUM | 4.3 | 0.1% | Aug 4, 2026 | The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handler... |
| CVE-2026-16035 | MEDIUM | 4.3 | 0.1% | Aug 4, 2026 | The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP ... |
| CVE-2026-15233 | MEDIUM | 4.8 | 0.2% | Aug 4, 2026 | The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML at... |
| CVE-2026-14939 | MEDIUM | 6.8 | 0.1% | Aug 4, 2026 | The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetchi... |
| CVE-2026-14872 | MEDIUM | 6.8 | 0.2% | Aug 4, 2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and e... |
| CVE-2026-14848 | MEDIUM | 5.4 | 0.1% | Aug 4, 2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified th... |
| CVE-2026-14824 | MEDIUM | 4.8 | 0.2% | Aug 4, 2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outp... |
| CVE-2026-14816 | MEDIUM | 6.5 | 0.1% | Aug 4, 2026 | The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of th... |
| CVE-2026-12698 | MEDIUM | 4.3 | 0.1% | Aug 4, 2026 | The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing thei... |
| CVE-2026-10526 | MEDIUM | 5.8 | 0.1% | Aug 4, 2026 | The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests th... |
| CVE-2026-18723 | MEDIUM | 6.3 | 0.2% | Aug 4, 2026 | A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file... |
| CVE-2026-18722 | MEDIUM | 6.3 | 0.2% | Aug 4, 2026 | A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurv... |
| CVE-2026-18721 | MEDIUM | 4.3 | 0.3% | Aug 4, 2026 | A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file... |
| CVE-2026-8508 | MEDIUM | 6.5 | 0.5% | Aug 4, 2026 | An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug... |
| CVE-2026-18720 | MEDIUM | 5.5 | 0.3% | Aug 4, 2026 | A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now