2026 CVE Vulnerabilities
43,297 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49332 | HIGH | 8.5 | 0.2% | Jul 28, 2026 | A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X... |
| CVE-2026-42493 | HIGH | 7.5 | — | Jul 28, 2026 | Addressing certain issues, in particular related to operations which may take excessively long and therefore would need ... |
| CVE-2026-42492 | HIGH | 7.5 | — | Jul 28, 2026 | Xenstore, to have an up-to-date picture of the entire system, wants to know of domains appearing and disappearing. To m... |
| CVE-2026-21047 | HIGH | 8.3 | 0.4% | Jul 28, 2026 | Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitra... |
| CVE-2026-15025 | HIGH | 7.5 | — | Jul 28, 2026 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to ... |
| CVE-2026-13440 | HIGH | 7.2 | — | Jul 28, 2026 | The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for ... |
| CVE-2026-63301 | HIGH | 7 | 0.4% | Jul 28, 2026 | In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding... |
| CVE-2026-59248 | HIGH | 8.7 | 0.3% | Jul 28, 2026 | Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP... |
| CVE-2026-14785 | HIGH | 7.5 | — | Jul 28, 2026 | The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all ver... |
| CVE-2026-14328 | HIGH | 8.8 | — | Jul 28, 2026 | The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privil... |
| CVE-2026-10207 | HIGH | 7.5 | — | Jul 28, 2026 | The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.... |
| CVE-2026-61376 | HIGH | 8.6 | 1.1% | Jul 28, 2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings.... |
| CVE-2026-59764 | HIGH | 8.6 | 1.1% | Jul 28, 2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vu... |
| CVE-2026-14516 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injec... |
| CVE-2026-14169 | HIGH | 8.1 | 0.3% | Jul 28, 2026 | Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted in... |
| CVE-2026-14168 | HIGH | 8.8 | 0.3% | Jul 28, 2026 | A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of th... |
| CVE-2026-14167 | HIGH | 8.8 | 0.3% | Jul 28, 2026 | A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level inclu... |
| CVE-2026-13161 | HIGH | 7.5 | 0.5% | Jul 28, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection vi... |
| CVE-2026-12800 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code'... |
| CVE-2026-12741 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via t... |
| CVE-2026-16585 | HIGH | 7.2 | 0.7% | Jul 28, 2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbi... |
| CVE-2026-14924 | HIGH | 7.5 | 0.2% | Jul 28, 2026 | The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in ... |
| CVE-2026-14870 | HIGH | 7.1 | 0.2% | Jul 28, 2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and e... |
| CVE-2026-14490 | HIGH | 7.5 | 0.5% | Jul 28, 2026 | The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory D... |
| CVE-2026-17524 | HIGH | 8.7 | 0.8% | Jul 28, 2026 | Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path va... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now