2026 CVE Vulnerabilities
43,297 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59560 | MEDIUM | 6.5 | — | Jul 27, 2026 | Subscriber Broken Access Control in FundEngine <= 1.7.8 versions. |
| CVE-2026-59559 | MEDIUM | 6.5 | — | Jul 27, 2026 | Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 version... |
| CVE-2026-59557 | MEDIUM | 6.5 | — | Jul 27, 2026 | Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. |
| CVE-2026-10819 | MEDIUM | 6.5 | 0.2% | Jul 27, 2026 | Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number o... |
| CVE-2026-10600 | MEDIUM | 4.3 | 0.2% | Jul 27, 2026 | Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and... |
| CVE-2026-17514 | MEDIUM | 5.3 | — | Jul 27, 2026 | A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Ex... |
| CVE-2026-15003 | MEDIUM | 5.6 | 0.1% | Jul 27, 2026 | A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125... |
| CVE-2026-66053 | MEDIUM | 5.9 | — | Jul 27, 2026 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affect... |
| CVE-2026-57917 | MEDIUM | 4.8 | 0.1% | Jul 27, 2026 | proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially a... |
| CVE-2026-57916 | MEDIUM | 4.6 | 0.1% | Jul 27, 2026 | proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare ar... |
| CVE-2026-55970 | MEDIUM | 6.5 | — | Jul 27, 2026 | Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users a... |
| CVE-2026-14856 | MEDIUM | 6.3 | — | Jul 27, 2026 | A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter ... |
| CVE-2026-12495 | MEDIUM | 5.3 | — | Jul 27, 2026 | Denial-of-service (DoS) vulnerability due to a stack buffer overflow in the http_gdpr_decrypt function of the Mercusys M... |
| CVE-2026-17534 | MEDIUM | 5.5 | — | Jul 27, 2026 | Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal ... |
| CVE-2026-65765 | MEDIUM | 6.9 | — | Jul 27, 2026 | Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths... |
| CVE-2026-65764 | MEDIUM | 5.1 | — | Jul 27, 2026 | Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user i... |
| CVE-2026-16554 | MEDIUM | 5.1 | 0.2% | Jul 27, 2026 | cJSON library is vulnerable to an integer overflow in the print_string_ptr() function in cJSON.c on 32-bit platforms. Th... |
| CVE-2026-14827 | MEDIUM | 6.8 | — | Jul 27, 2026 | The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it in... |
| CVE-2026-14820 | MEDIUM | 5.3 | — | Jul 27, 2026 | The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-log... |
| CVE-2026-14568 | MEDIUM | 6.5 | — | Jul 27, 2026 | The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration Wor... |
| CVE-2026-14236 | MEDIUM | 4.7 | — | Jul 27, 2026 | The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it... |
| CVE-2026-14203 | MEDIUM | 4.8 | — | Jul 27, 2026 | The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML... |
| CVE-2026-14190 | MEDIUM | 6.1 | — | Jul 27, 2026 | The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input... |
| CVE-2026-13400 | MEDIUM | 6.1 | — | Jul 27, 2026 | Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and incl... |
| CVE-2026-13390 | MEDIUM | 5.3 | — | Jul 27, 2026 | The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggrega... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now