2026 CVE Vulnerabilities
53,439 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15394 | MEDIUM | 6.4 | — | Jul 23, 2026 | The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2026-15348 | MEDIUM | 6.3 | — | Jul 23, 2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all... |
| CVE-2026-15017 | HIGH | 8.8 | — | Jul 23, 2026 | The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin... |
| CVE-2026-15015 | CRITICAL | 9.8 | — | Jul 23, 2026 | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions u... |
| CVE-2026-15011 | CRITICAL | 9.8 | 1.0% | Jul 23, 2026 | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parame... |
| CVE-2026-14481 | MEDIUM | 6.4 | 0.4% | Jul 23, 2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl... |
| CVE-2026-14282 | CRITICAL | 9.8 | 1.3% | Jul 23, 2026 | The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for ... |
| CVE-2026-13119 | MEDIUM | 6.5 | — | Jul 23, 2026 | The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'stan... |
| CVE-2026-13009 | MEDIUM | 6.5 | — | Jul 23, 2026 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Param... |
| CVE-2026-52688 | HIGH | 7.5 | 0.4% | Jul 23, 2026 | RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation |
| CVE-2026-52686 | LOW | 3.7 | 0.3% | Jul 23, 2026 | The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signat... |
| CVE-2026-52684 | LOW | 3.7 | 0.2% | Jul 23, 2026 | If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data... |
| CVE-2026-16723 | CRITICAL | 9 | 0.7% | Jul 23, 2026 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable ... |
| CVE-2026-16287 | HIGH | 7.8 | 0.8% | Jul 23, 2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG... |
| CVE-2026-9729 | MEDIUM | 6.4 | 0.3% | Jul 23, 2026 | The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_noti... |
| CVE-2026-9713 | HIGH | 7.5 | 0.5% | Jul 23, 2026 | The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table'... |
| CVE-2026-9635 | MEDIUM | 6.4 | 0.3% | Jul 23, 2026 | The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parame... |
| CVE-2026-59678 | HIGH | 7.1 | 0.2% | Jul 23, 2026 | An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary fi... |
| CVE-2026-59677 | MEDIUM | 6.8 | 0.1% | Jul 23, 2026 | A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined ... |
| CVE-2026-12421 | HIGH | 7.2 | 0.3% | Jul 23, 2026 | The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all version... |
| CVE-2026-9577 | MEDIUM | 4.8 | 0.2% | Jul 23, 2026 | The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before ref... |
| CVE-2026-9066 | MEDIUM | 6.1 | 0.2% | Jul 23, 2026 | The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asse... |
| CVE-2026-59676 | MEDIUM | 5.8 | 0.1% | Jul 23, 2026 | A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user ... |
| CVE-2026-14291 | HIGH | 7.5 | 0.3% | Jul 23, 2026 | The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its ... |
| CVE-2026-12082 | HIGH | 7.5 | 0.2% | Jul 23, 2026 | The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now