2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58246 | MEDIUM | 4.3 | — | Jul 28, 2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagn... |
| CVE-2026-16462 | CRITICAL | 9.8 | 0.4% | Jul 28, 2026 | In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker ... |
| CVE-2026-14785 | HIGH | 7.5 | — | Jul 28, 2026 | The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all ver... |
| CVE-2026-14328 | HIGH | 8.8 | — | Jul 28, 2026 | The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privil... |
| CVE-2026-11841 | CRITICAL | 9.4 | 0.5% | Jul 28, 2026 | An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileac... |
| CVE-2026-11598 | MEDIUM | 5 | — | Jul 28, 2026 | The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all ... |
| CVE-2026-10207 | HIGH | 7.5 | — | Jul 28, 2026 | The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.... |
| CVE-2026-9680 | MEDIUM | 5.8 | 0.2% | Jul 28, 2026 | Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP... |
| CVE-2026-8167 | MEDIUM | 6.1 | 0.1% | Jul 28, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solu... |
| CVE-2026-61376 | HIGH | 8.6 | 1.1% | Jul 28, 2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings.... |
| CVE-2026-59764 | HIGH | 8.6 | 1.1% | Jul 28, 2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vu... |
| CVE-2026-44387 | MEDIUM | 5.2 | 0.1% | Jul 28, 2026 | ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. I... |
| CVE-2026-15267 | MEDIUM | 6.5 | 0.3% | Jul 28, 2026 | The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL ... |
| CVE-2026-14516 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injec... |
| CVE-2026-14171 | MEDIUM | 6.1 | 0.2% | Jul 28, 2026 | An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick ... |
| CVE-2026-14170 | — | — | — | Jul 28, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-14169 | HIGH | 8.1 | 0.3% | Jul 28, 2026 | Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted in... |
| CVE-2026-14168 | HIGH | 8.8 | 0.3% | Jul 28, 2026 | A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of th... |
| CVE-2026-14167 | HIGH | 8.8 | 0.3% | Jul 28, 2026 | A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level inclu... |
| CVE-2026-13161 | HIGH | 7.5 | 0.5% | Jul 28, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection vi... |
| CVE-2026-12800 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code'... |
| CVE-2026-55977 | LOW | 3.3 | 0.1% | Jul 28, 2026 | Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the applicatio... |
| CVE-2026-15730 | MEDIUM | 6.4 | 0.2% | Jul 28, 2026 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ... |
| CVE-2026-15673 | MEDIUM | 4.4 | 0.3% | Jul 28, 2026 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera... |
| CVE-2026-15671 | MEDIUM | 4.9 | 0.3% | Jul 28, 2026 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now