2026 CVE Vulnerabilities
43,308 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15821 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2026-15739 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' ... |
| CVE-2026-15346 | MEDIUM | 6.1 | 0.3% | Jul 24, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '... |
| CVE-2026-12702 | MEDIUM | 5.1 | 0.2% | Jul 24, 2026 | In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to... |
| CVE-2026-16910 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers acc... |
| CVE-2026-15755 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Short... |
| CVE-2026-15665 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2026-15653 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2026-15648 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attri... |
| CVE-2026-15464 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Att... |
| CVE-2026-15334 | MEDIUM | 6.4 | 0.3% | Jul 24, 2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress... |
| CVE-2026-15333 | MEDIUM | 6.4 | 0.3% | Jul 24, 2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress... |
| CVE-2026-12654 | MEDIUM | 5.3 | 0.4% | Jul 24, 2026 | The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up... |
| CVE-2026-12689 | MEDIUM | 5.4 | 0.1% | Jul 24, 2026 | The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its pr... |
| CVE-2026-12688 | MEDIUM | 6.5 | 0.1% | Jul 24, 2026 | The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group mem... |
| CVE-2026-66139 | MEDIUM | 4.8 | 0.3% | Jul 24, 2026 | OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known. |
| CVE-2026-54422 | MEDIUM | 5.5 | — | Jul 24, 2026 | In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, m... |
| CVE-2026-6454 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and inclu... |
| CVE-2026-15420 | MEDIUM | 4.3 | 0.6% | Jul 24, 2026 | The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory ... |
| CVE-2026-15100 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnore... |
| CVE-2026-13464 | MEDIUM | 5.3 | 0.3% | Jul 24, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Ob... |
| CVE-2026-11922 | MEDIUM | 6.5 | — | Jul 24, 2026 | A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST... |
| CVE-2026-11354 | MEDIUM | 5.3 | 0.2% | Jul 24, 2026 | The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an... |
| CVE-2026-49159 | MEDIUM | 6.5 | 0.6% | Jul 24, 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose ... |
| CVE-2026-44955 | MEDIUM | 6.9 | 0.2% | Jul 23, 2026 | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now