2026 CVE Vulnerabilities
43,284 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13395 | HIGH | 8.6 | 0.2% | Jul 30, 2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a ... |
| CVE-2026-13178 | HIGH | 7.5 | 0.1% | Jul 30, 2026 | The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied ... |
| CVE-2026-12687 | HIGH | 7.5 | — | Jul 30, 2026 | The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into th... |
| CVE-2026-12500 | HIGH | 7.5 | 0.1% | Jul 30, 2026 | The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a... |
| CVE-2026-67248 | HIGH | 8.8 | 0.2% | Jul 30, 2026 | A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because ... |
| CVE-2026-67245 | HIGH | 8.1 | 0.2% | Jul 30, 2026 | A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled... |
| CVE-2026-1360 | HIGH | 7.5 | 0.6% | Jul 30, 2026 | The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and includ... |
| CVE-2026-14356 | HIGH | 8.8 | — | Jul 30, 2026 | The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.... |
| CVE-2026-67244 | HIGH | 7.2 | 0.2% | Jul 30, 2026 | A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user... |
| CVE-2026-48448 | HIGH | 8.6 | 0.4% | Jul 30, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ... |
| CVE-2026-18188 | HIGH | 8.1 | 0.2% | Jul 30, 2026 | A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled... |
| CVE-2026-18187 | HIGH | 8.1 | 0.2% | Jul 30, 2026 | A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-control... |
| CVE-2026-18186 | HIGH | 8.1 | 0.2% | Jul 30, 2026 | A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-contr... |
| CVE-2026-16727 | HIGH | 7.3 | 0.1% | Jul 30, 2026 | Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows... |
| CVE-2026-15929 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics Sma... |
| CVE-2026-18017 | HIGH | 8.8 | 0.2% | Jul 30, 2026 | Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code insid... |
| CVE-2026-18012 | HIGH | 8.8 | 0.2% | Jul 30, 2026 | Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-17995 | HIGH | 8.1 | 0.2% | Jul 30, 2026 | Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds... |
| CVE-2026-17993 | HIGH | 7 | 0.1% | Jul 30, 2026 | Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalat... |
| CVE-2026-17989 | HIGH | 8.8 | 0.2% | Jul 30, 2026 | Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside ... |
| CVE-2026-17979 | HIGH | 7.5 | 0.2% | Jul 30, 2026 | Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox ... |
| CVE-2026-17971 | HIGH | 8.8 | 0.2% | Jul 30, 2026 | Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially p... |
| CVE-2026-17969 | HIGH | 8.8 | 0.2% | Jul 30, 2026 | Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute a... |
| CVE-2026-17967 | HIGH | 8.8 | 0.3% | Jul 30, 2026 | Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially... |
| CVE-2026-17956 | HIGH | 8.8 | 0.2% | Jul 30, 2026 | Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now