2026 CVE Vulnerabilities
43,031 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15054 | LOW | 3.7 | 0.2% | Jul 30, 2026 | The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submiss... |
| CVE-2026-14222 | LOW | 3.8 | 0.2% | Jul 30, 2026 | The Easy Appointments WordPress plugin before 3.12.28 does not perform any capability or nonce check in one of its conne... |
| CVE-2026-14221 | LOW | 3.8 | 0.2% | Jul 30, 2026 | The Easy Appointments WordPress plugin through 4.0 does not perform capability checks in several of its appointment-mana... |
| CVE-2026-14188 | LOW | 2.7 | 0.2% | Jul 30, 2026 | The Easy Appointments WordPress plugin before 3.12.28 does not perform a per-request capability or nonce check on one of... |
| CVE-2026-18011 | LOW | 2.4 | 0.1% | Jul 30, 2026 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker t... |
| CVE-2026-18000 | LOW | 3.1 | 0.1% | Jul 30, 2026 | Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who ... |
| CVE-2026-17997 | LOW | 3.1 | 0.1% | Jul 30, 2026 | Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had comp... |
| CVE-2026-17984 | LOW | 3.3 | 0.1% | Jul 30, 2026 | Inappropriate implementation in Browser in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to l... |
| CVE-2026-17980 | LOW | 3.1 | 0.2% | Jul 30, 2026 | Inappropriate implementation in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who conv... |
| CVE-2026-17957 | LOW | 3.1 | 0.1% | Jul 30, 2026 | Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromis... |
| CVE-2026-17902 | LOW | 3.5 | 0.2% | Jul 30, 2026 | Inappropriate implementation in Editing in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to le... |
| CVE-2026-17860 | LOW | 3.3 | 0.1% | Jul 30, 2026 | Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a local ... |
| CVE-2026-17826 | LOW | 3.1 | 0.1% | Jul 30, 2026 | Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker ... |
| CVE-2026-17766 | LOW | 3.3 | 0.1% | Jul 30, 2026 | Insufficient validation of untrusted input in Clipboard in Google Chrome on Android prior to 151.0.7922.72 allowed a loc... |
| CVE-2026-17732 | LOW | 3.1 | 0.1% | Jul 30, 2026 | Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-orig... |
| CVE-2026-17720 | LOW | 3.1 | 0.1% | Jul 30, 2026 | Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had c... |
| CVE-2026-17715 | LOW | 3.1 | 0.2% | Jul 30, 2026 | Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convince... |
| CVE-2026-17702 | LOW | 3.1 | 0.2% | Jul 30, 2026 | Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromis... |
| CVE-2026-62995 | LOW | 2.3 | 0.1% | Jul 29, 2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar... |
| CVE-2026-10684 | LOW | 3 | — | Jul 29, 2026 | In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a stored Zephyr coredu... |
| CVE-2026-52791 | LOW | 2 | — | Jul 29, 2026 | fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branc... |
| CVE-2026-63241 | LOW | 3.1 | 0.1% | Jul 29, 2026 | An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course compl... |
| CVE-2026-63236 | LOW | 3.7 | 0.2% | Jul 29, 2026 | An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name,... |
| CVE-2026-63235 | LOW | 3.7 | 0.2% | Jul 29, 2026 | An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the se... |
| CVE-2026-63228 | LOW | 2.6 | 0.1% | Jul 29, 2026 | An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now