2026 CVE Vulnerabilities
51,070 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18217 | MEDIUM | 4.7 | 0.2% | Jul 31, 2026 | A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution... |
| CVE-2026-18215 | HIGH | 8.1 | 0.2% | Jul 31, 2026 | Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization... |
| CVE-2026-18214 | HIGH | 8.1 | 0.2% | Jul 31, 2026 | Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Wor... |
| CVE-2026-18211 | MEDIUM | 5.4 | 0.2% | Jul 31, 2026 | A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is respo... |
| CVE-2026-18209 | MEDIUM | 4.7 | 0.2% | Jul 31, 2026 | A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flow... |
| CVE-2026-18208 | MEDIUM | 6.5 | 0.2% | Jul 31, 2026 | A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source... |
| CVE-2026-18206 | LOW | 3.7 | 0.2% | Jul 31, 2026 | A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services.... |
| CVE-2026-18203 | MEDIUM | 6.5 | 0.2% | Jul 31, 2026 | A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a gr... |
| CVE-2026-16105 | MEDIUM | 4.9 | 0.2% | Jul 31, 2026 | A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoin... |
| CVE-2026-8155 | MEDIUM | 5.4 | 0.1% | Jul 31, 2026 | The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints... |
| CVE-2026-18452 | CRITICAL | 10 | 0.4% | Jul 31, 2026 | DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote att... |
| CVE-2026-16236 | HIGH | 8.8 | 0.6% | Jul 31, 2026 | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5... |
| CVE-2026-15381 | LOW | 3.7 | 0.2% | Jul 31, 2026 | The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a S... |
| CVE-2026-15258 | HIGH | 8.1 | 0.2% | Jul 31, 2026 | The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-fe... |
| CVE-2026-15209 | MEDIUM | 6.5 | 0.2% | Jul 31, 2026 | The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a... |
| CVE-2026-15048 | HIGH | 7.5 | 0.3% | Jul 31, 2026 | The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowin... |
| CVE-2026-14931 | MEDIUM | 6.5 | 0.2% | Jul 31, 2026 | The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation ... |
| CVE-2026-14930 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front... |
| CVE-2026-14929 | MEDIUM | 4.3 | 0.2% | Jul 31, 2026 | The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allo... |
| CVE-2026-14928 | MEDIUM | 6.5 | 0.2% | Jul 31, 2026 | The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning supp... |
| CVE-2026-14927 | LOW | 3.7 | 0.2% | Jul 31, 2026 | The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership che... |
| CVE-2026-14922 | MEDIUM | 6.1 | 0.1% | Jul 31, 2026 | WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 throug... |
| CVE-2026-14921 | MEDIUM | 6.1 | 0.1% | Jul 31, 2026 | The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_... |
| CVE-2026-14919 | CRITICAL | 9.8 | 0.3% | Jul 31, 2026 | The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it be... |
| CVE-2026-14862 | LOW | 3.7 | 0.2% | Jul 31, 2026 | The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downlo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now