2026 CVE Vulnerabilities
43,286 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62423 | MEDIUM | 5.5 | — | Jul 28, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-42495 | MEDIUM | 5.5 | — | Jul 28, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-42494 | MEDIUM | 6.1 | — | Jul 28, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-41874 | MEDIUM | 6.8 | 0.1% | Jul 28, 2026 | Quick.Cart stores hard-coded, plaintext admin credentials in a configuration file. This flaw allows attackers with acces... |
| CVE-2026-18047 | MEDIUM | 6.5 | — | Jul 28, 2026 | A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching fo... |
| CVE-2026-18038 | MEDIUM | 4.3 | — | Jul 28, 2026 | A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.E... |
| CVE-2026-15393 | MEDIUM | 6.4 | — | Jul 28, 2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress... |
| CVE-2026-15016 | MEDIUM | 6.4 | — | Jul 28, 2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab... |
| CVE-2026-4648 | MEDIUM | 6.8 | — | Jul 28, 2026 | Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tec... |
| CVE-2026-16774 | MEDIUM | 5.3 | — | Jul 28, 2026 | The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the ... |
| CVE-2026-16773 | MEDIUM | 5.3 | — | Jul 28, 2026 | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive In... |
| CVE-2026-15444 | MEDIUM | 4.9 | — | Jul 28, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the... |
| CVE-2026-15411 | MEDIUM | 5.3 | — | Jul 28, 2026 | The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for ... |
| CVE-2026-13110 | MEDIUM | 5.3 | — | Jul 28, 2026 | The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and includin... |
| CVE-2026-63303 | MEDIUM | 5.1 | 0.4% | Jul 28, 2026 | A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fai... |
| CVE-2026-63302 | MEDIUM | 5.1 | 0.3% | Jul 28, 2026 | Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated at... |
| CVE-2026-18029 | MEDIUM | 6.3 | 0.2% | Jul 28, 2026 | Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a s... |
| CVE-2026-65624 | MEDIUM | 6.9 | 0.4% | Jul 28, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote ... |
| CVE-2026-58246 | MEDIUM | 4.3 | — | Jul 28, 2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagn... |
| CVE-2026-11598 | MEDIUM | 5 | — | Jul 28, 2026 | The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all ... |
| CVE-2026-9680 | MEDIUM | 5.8 | 0.2% | Jul 28, 2026 | Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP... |
| CVE-2026-8167 | MEDIUM | 6.1 | 0.1% | Jul 28, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solu... |
| CVE-2026-44387 | MEDIUM | 5.2 | 0.1% | Jul 28, 2026 | ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. I... |
| CVE-2026-15267 | MEDIUM | 6.5 | 0.3% | Jul 28, 2026 | The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL ... |
| CVE-2026-14171 | MEDIUM | 6.1 | 0.2% | Jul 28, 2026 | An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now