2026 CVE Vulnerabilities
56,974 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11575 | HIGH | 7.5 | 0.1% | Jul 17, 2026 | The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming paymen... |
| CVE-2026-10525 | MEDIUM | 6.1 | 0.2% | Jul 17, 2026 | The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and... |
| CVE-2026-15982 | CRITICAL | 9.8 | 0.3% | Jul 17, 2026 | The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable ... |
| CVE-2026-15094 | MEDIUM | 6.1 | 0.2% | Jul 17, 2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parame... |
| CVE-2026-60060 | MEDIUM | 6.3 | 0.3% | Jul 17, 2026 | Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provide... |
| CVE-2026-58317 | MEDIUM | 6.3 | 0.3% | Jul 17, 2026 | Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Pr... |
| CVE-2026-41993 | MEDIUM | 6.7 | 0.1% | Jul 17, 2026 | Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a loc... |
| CVE-2026-21770 | MEDIUM | 6.5 | 0.1% | Jul 17, 2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker ... |
| CVE-2026-15759 | MEDIUM | 6.4 | 0.2% | Jul 17, 2026 | The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable t... |
| CVE-2026-15457 | MEDIUM | 4.9 | 0.8% | Jul 17, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversa... |
| CVE-2026-15349 | MEDIUM | 4.3 | 0.3% | Jul 17, 2026 | The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization b... |
| CVE-2026-15161 | MEDIUM | 6.4 | 0.2% | Jul 17, 2026 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and ... |
| CVE-2026-14503 | MEDIUM | 6.5 | 0.3% | Jul 17, 2026 | The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc... |
| CVE-2026-13765 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive... |
| CVE-2026-13352 | HIGH | 8.8 | 0.6% | Jul 17, 2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres... |
| CVE-2026-8616 | MEDIUM | 5.3 | 0.2% | Jul 17, 2026 | The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2026-15395 | HIGH | 7.2 | 0.2% | Jul 17, 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2026-15160 | MEDIUM | 4.3 | 0.5% | Jul 17, 2026 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl... |
| CVE-2026-15159 | MEDIUM | 4.3 | 0.2% | Jul 17, 2026 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up... |
| CVE-2026-11324 | MEDIUM | 6.1 | 0.3% | Jul 17, 2026 | The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cros... |
| CVE-2026-62387 | HIGH | 7.1 | 0.3% | Jul 17, 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default C... |
| CVE-2026-62386 | HIGH | 8.2 | 0.3% | Jul 17, 2026 | The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query... |
| CVE-2026-62241 | CRITICAL | 9.3 | 6.5% | Jul 17, 2026 | clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me')... |
| CVE-2026-62238 | HIGH | 8.8 | 0.2% | Jul 17, 2026 | OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint ... |
| CVE-2026-62237 | MEDIUM | 6.5 | 0.2% | Jul 17, 2026 | Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now