2026 CVE Vulnerabilities
43,311 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15646 | MEDIUM | 6.4 | 0.3% | Jul 23, 2026 | The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attri... |
| CVE-2026-15448 | MEDIUM | 6.5 | — | Jul 23, 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order... |
| CVE-2026-15404 | MEDIUM | 6.4 | 0.3% | Jul 23, 2026 | The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and inc... |
| CVE-2026-15394 | MEDIUM | 6.4 | — | Jul 23, 2026 | The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2026-15348 | MEDIUM | 6.3 | — | Jul 23, 2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all... |
| CVE-2026-14481 | MEDIUM | 6.4 | 0.4% | Jul 23, 2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl... |
| CVE-2026-13119 | MEDIUM | 6.5 | — | Jul 23, 2026 | The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'stan... |
| CVE-2026-13009 | MEDIUM | 6.5 | — | Jul 23, 2026 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Param... |
| CVE-2026-9729 | MEDIUM | 6.4 | 0.3% | Jul 23, 2026 | The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_noti... |
| CVE-2026-9635 | MEDIUM | 6.4 | 0.3% | Jul 23, 2026 | The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parame... |
| CVE-2026-59677 | MEDIUM | 6.8 | 0.1% | Jul 23, 2026 | A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined ... |
| CVE-2026-9577 | MEDIUM | 4.8 | 0.2% | Jul 23, 2026 | The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before ref... |
| CVE-2026-9066 | MEDIUM | 6.1 | 0.2% | Jul 23, 2026 | The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asse... |
| CVE-2026-59676 | MEDIUM | 5.8 | 0.1% | Jul 23, 2026 | A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user ... |
| CVE-2026-63226 | MEDIUM | 6.9 | 0.4% | Jul 23, 2026 | Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port for... |
| CVE-2026-6390 | MEDIUM | 6.8 | 0.2% | Jul 23, 2026 | A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one ... |
| CVE-2026-7120 | MEDIUM | 5.3 | 0.2% | Jul 23, 2026 | @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the ... |
| CVE-2026-21723 | MEDIUM | 5.3 | 0.3% | Jul 23, 2026 | The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates ... |
| CVE-2026-16653 | MEDIUM | 5.5 | 0.7% | Jul 23, 2026 | A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the ... |
| CVE-2026-16631 | MEDIUM | 5.3 | 1.1% | Jul 23, 2026 | A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/p... |
| CVE-2026-38763 | MEDIUM | 5.5 | 0.2% | Jul 22, 2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the... |
| CVE-2026-16630 | MEDIUM | 5.3 | 1.1% | Jul 22, 2026 | A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the funct... |
| CVE-2026-16629 | MEDIUM | 5.3 | 0.6% | Jul 22, 2026 | A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the ... |
| CVE-2026-16628 | MEDIUM | 5.3 | 1.1% | Jul 22, 2026 | A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec o... |
| CVE-2026-64795 | MEDIUM | 5.4 | 0.1% | Jul 22, 2026 | Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provide... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now