2026 CVE Vulnerabilities
55,748 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56392 | LOW | 1.8 | 0.1% | Jul 24, 2026 | GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation... |
| CVE-2026-56391 | MEDIUM | 4.6 | 0.1% | Jul 24, 2026 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--ch... |
| CVE-2026-49745 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ... |
| CVE-2026-49744 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ... |
| CVE-2026-49743 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of... |
| CVE-2026-24727 | CRITICAL | 9.3 | 0.7% | Jul 24, 2026 | An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporat... |
| CVE-2026-15821 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2026-15739 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' ... |
| CVE-2026-15704 | CRITICAL | 9.8 | 0.4% | Jul 24, 2026 | In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authori... |
| CVE-2026-15346 | MEDIUM | 6.1 | 0.3% | Jul 24, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '... |
| CVE-2026-12702 | MEDIUM | 4.9 | 0.2% | Jul 24, 2026 | In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to... |
| CVE-2026-16910 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers acc... |
| CVE-2026-16519 | HIGH | 7.3 | 0.1% | Jul 24, 2026 | A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads on... |
| CVE-2026-15755 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Short... |
| CVE-2026-15665 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2026-15653 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2026-15648 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attri... |
| CVE-2026-15464 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Att... |
| CVE-2026-15334 | MEDIUM | 6.4 | 0.3% | Jul 24, 2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress... |
| CVE-2026-15333 | MEDIUM | 6.4 | 0.3% | Jul 24, 2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress... |
| CVE-2026-12654 | MEDIUM | 5.3 | 0.4% | Jul 24, 2026 | The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up... |
| CVE-2026-14603 | HIGH | 7.5 | 0.1% | Jul 24, 2026 | The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint... |
| CVE-2026-14172 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without ... |
| CVE-2026-12981 | HIGH | 7.5 | 0.2% | Jul 24, 2026 | The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user pas... |
| CVE-2026-12877 | CRITICAL | 9.1 | 0.1% | Jul 24, 2026 | The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user s... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now