2026 CVE Vulnerabilities
43,031 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66401 | LOW | 2.4 | 0.2% | Aug 1, 2026 | FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fail... |
| CVE-2026-14823 | LOW | 2.2 | 0.1% | Aug 1, 2026 | The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of it... |
| CVE-2026-14214 | LOW | 2.7 | 0.1% | Aug 1, 2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be wr... |
| CVE-2026-14197 | LOW | 3.8 | 0.1% | Aug 1, 2026 | The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket... |
| CVE-2026-14195 | LOW | 2.7 | 0.1% | Aug 1, 2026 | The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning p... |
| CVE-2026-11882 | LOW | 3.7 | 0.2% | Aug 1, 2026 | The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes... |
| CVE-2026-10827 | LOW | 3.5 | 0.1% | Aug 1, 2026 | The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before usi... |
| CVE-2026-54787 | LOW | 3.1 | — | Jul 31, 2026 | sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle s... |
| CVE-2026-55825 | LOW | 3.1 | — | Jul 31, 2026 | Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can ... |
| CVE-2026-57232 | LOW | 3.1 | 0.2% | Jul 31, 2026 | Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end mod... |
| CVE-2026-55824 | LOW | 2.6 | — | Jul 31, 2026 | Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth cre... |
| CVE-2026-25552 | LOW | 3.7 | — | Jul 31, 2026 | Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rat... |
| CVE-2026-56569 | LOW | 3.3 | 0.1% | Jul 31, 2026 | HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal config... |
| CVE-2026-56567 | LOW | 3.3 | 0.1% | Jul 31, 2026 | HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of intern... |
| CVE-2026-65636 | LOW | 2.1 | 0.1% | Jul 31, 2026 | Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ymlr (Elixir.Ymlr module) allows attackers to inj... |
| CVE-2026-18206 | LOW | 3.7 | 0.2% | Jul 31, 2026 | A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services.... |
| CVE-2026-15381 | LOW | 3.7 | 0.2% | Jul 31, 2026 | The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a S... |
| CVE-2026-14927 | LOW | 3.7 | — | Jul 31, 2026 | The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership che... |
| CVE-2026-14862 | LOW | 3.7 | 0.1% | Jul 31, 2026 | The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downlo... |
| CVE-2026-14849 | LOW | 3.7 | — | Jul 31, 2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it... |
| CVE-2026-13393 | LOW | 3.5 | 0.2% | Jul 31, 2026 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item... |
| CVE-2026-58039 | LOW | 3.3 | 0.2% | Jul 31, 2026 | A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-wr... |
| CVE-2026-41709 | LOW | 2.7 | — | Jul 30, 2026 | VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform... |
| CVE-2026-59326 | LOW | 3.3 | — | Jul 30, 2026 | The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment vari... |
| CVE-2026-56847 | LOW | 3.3 | 0.2% | Jul 30, 2026 | A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now