2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10774 | MEDIUM | 6.5 | 0.2% | Aug 2, 2026 | Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/blue... |
| CVE-2026-68583 | MEDIUM | 5.4 | 0.1% | Aug 2, 2026 | luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field th... |
| CVE-2026-12231 | MEDIUM | 6.4 | 0.3% | Aug 2, 2026 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_info... |
| CVE-2026-18573 | MEDIUM | 6.5 | 0.2% | Aug 2, 2026 | A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authoriza... |
| CVE-2026-18572 | MEDIUM | 6.5 | 0.2% | Aug 2, 2026 | Keycloak provides authorization services that allow administrators to restrict access to resources based on time policie... |
| CVE-2026-18570 | MEDIUM | 5.4 | 0.2% | Aug 2, 2026 | A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This componen... |
| CVE-2026-16292 | MEDIUM | 5.4 | 0.1% | Aug 2, 2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-meta... |
| CVE-2026-16291 | MEDIUM | 4.3 | 0.1% | Aug 2, 2026 | The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user befo... |
| CVE-2026-16273 | MEDIUM | 4.6 | 0.2% | Aug 2, 2026 | The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field ... |
| CVE-2026-16064 | MEDIUM | 5.4 | 0.1% | Aug 2, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the o... |
| CVE-2026-16063 | MEDIUM | 5.4 | 0.2% | Aug 2, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline cont... |
| CVE-2026-16062 | MEDIUM | 6.6 | 0.2% | Aug 2, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-co... |
| CVE-2026-16042 | MEDIUM | 4.3 | 0.1% | Aug 2, 2026 | The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowin... |
| CVE-2026-15385 | MEDIUM | 5.4 | 0.2% | Aug 2, 2026 | The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-m... |
| CVE-2026-15248 | MEDIUM | 5.5 | 0.2% | Aug 2, 2026 | The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment ... |
| CVE-2026-14938 | MEDIUM | 4.3 | 0.1% | Aug 2, 2026 | The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation be... |
| CVE-2026-14864 | MEDIUM | 5.4 | 0.2% | Aug 2, 2026 | The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its s... |
| CVE-2026-14841 | MEDIUM | 6.1 | 0.2% | Aug 2, 2026 | The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before refle... |
| CVE-2026-14817 | MEDIUM | 6.8 | 0.2% | Aug 2, 2026 | The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through cer... |
| CVE-2026-13389 | MEDIUM | 6.5 | 0.2% | Aug 2, 2026 | The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST ... |
| CVE-2026-11872 | MEDIUM | 4.3 | 0.1% | Aug 2, 2026 | The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in ... |
| CVE-2026-9335 | MEDIUM | 6.5 | 0.6% | Aug 2, 2026 | A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improp... |
| CVE-2026-67353 | MEDIUM | 6.9 | 0.2% | Aug 1, 2026 | guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimit... |
| CVE-2026-67339 | MEDIUM | 6.9 | 0.2% | Aug 1, 2026 | guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cUR... |
| CVE-2026-67338 | MEDIUM | 6.1 | 0.2% | Aug 1, 2026 | JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to vali... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now