2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-65311 | MEDIUM | 5.3 | 0.3% | Jul 31, 2026 | The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoi... |
| CVE-2026-18218 | MEDIUM | 5.4 | 0.1% | Jul 31, 2026 | A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attemp... |
| CVE-2026-18217 | MEDIUM | 4.7 | 0.2% | Jul 31, 2026 | A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution... |
| CVE-2026-18211 | MEDIUM | 5.4 | 0.2% | Jul 31, 2026 | A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is respo... |
| CVE-2026-18209 | MEDIUM | 4.7 | 0.2% | Jul 31, 2026 | A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flow... |
| CVE-2026-18208 | MEDIUM | 6.5 | 0.2% | Jul 31, 2026 | A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source... |
| CVE-2026-18203 | MEDIUM | 6.5 | 0.2% | Jul 31, 2026 | A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a gr... |
| CVE-2026-16105 | MEDIUM | 4.9 | 0.2% | Jul 31, 2026 | A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoin... |
| CVE-2026-8155 | MEDIUM | 5.4 | 0.1% | Jul 31, 2026 | The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints... |
| CVE-2026-15209 | MEDIUM | 6.5 | 0.1% | Jul 31, 2026 | The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a... |
| CVE-2026-14931 | MEDIUM | 6.5 | 0.1% | Jul 31, 2026 | The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation ... |
| CVE-2026-14929 | MEDIUM | 4.3 | — | Jul 31, 2026 | The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allo... |
| CVE-2026-14928 | MEDIUM | 6.5 | 0.1% | Jul 31, 2026 | The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning supp... |
| CVE-2026-14922 | MEDIUM | 6.1 | 0.2% | Jul 31, 2026 | WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 throug... |
| CVE-2026-14921 | MEDIUM | 6.1 | 0.2% | Jul 31, 2026 | The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_... |
| CVE-2026-14847 | MEDIUM | 4.3 | — | Jul 31, 2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of i... |
| CVE-2026-14845 | MEDIUM | 6.1 | 0.2% | Jul 31, 2026 | The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor re... |
| CVE-2026-14843 | MEDIUM | 5.3 | — | Jul 31, 2026 | The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the target... |
| CVE-2026-14834 | MEDIUM | 6.5 | 0.1% | Jul 31, 2026 | The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX ... |
| CVE-2026-14833 | MEDIUM | 6.8 | — | Jul 31, 2026 | The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rend... |
| CVE-2026-14554 | MEDIUM | 6.5 | 0.2% | Jul 31, 2026 | The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them... |
| CVE-2026-14317 | MEDIUM | 5.3 | — | Jul 31, 2026 | The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by t... |
| CVE-2026-12697 | MEDIUM | 5.4 | 0.1% | Jul 31, 2026 | The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting us... |
| CVE-2026-12376 | MEDIUM | 4.3 | 0.1% | Jul 31, 2026 | The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing... |
| CVE-2026-63220 | MEDIUM | 4.8 | — | Jul 31, 2026 | CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-For... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now