2026 CVE Vulnerabilities
62,192 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10078 | LOW | 2.7 | 0.2% | May 29, 2026 | A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, spec... |
| CVE-2026-9189 | MEDIUM | 5.3 | 0.2% | May 29, 2026 | The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verifi... |
| CVE-2026-6075 | HIGH | 8.1 | 0.2% | May 29, 2026 | The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl... |
| CVE-2026-49200 | CRITICAL | 9.8 | 0.5% | May 29, 2026 | The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file conta... |
| CVE-2026-49199 | CRITICAL | 9.8 | 1.3% | May 29, 2026 | Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device. |
| CVE-2026-49198 | MEDIUM | 4.9 | 0.2% | May 29, 2026 | Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorize... |
| CVE-2026-49197 | CRITICAL | 9.8 | 0.3% | May 29, 2026 | Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requ... |
| CVE-2026-49196 | HIGH | 7.2 | 0.4% | May 29, 2026 | The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary she... |
| CVE-2026-49195 | HIGH | 8.8 | 0.2% | May 29, 2026 | Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any... |
| CVE-2026-10058 | MEDIUM | 4.8 | 0.2% | May 29, 2026 | ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privi... |
| CVE-2026-10057 | MEDIUM | 4.8 | 0.2% | May 29, 2026 | ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privi... |
| CVE-2026-10056 | HIGH | 7.5 | 0.2% | May 29, 2026 | CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default ... |
| CVE-2026-10052 | MEDIUM | 4.1 | 0.2% | May 29, 2026 | A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can... |
| CVE-2026-10039 | MEDIUM | 4.9 | 0.3% | May 29, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter i... |
| CVE-2026-9243 | MEDIUM | 6.4 | 0.3% | May 29, 2026 | The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direct... |
| CVE-2026-4776 | HIGH | 7.1 | 0.2% | May 29, 2026 | An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitiz... |
| CVE-2026-49322 | MEDIUM | 4.3 | 0.1% | May 29, 2026 | Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year al... |
| CVE-2026-3655 | CRITICAL | 9.8 | 0.5% | May 29, 2026 | The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in version... |
| CVE-2026-9714 | MEDIUM | 6.4 | 0.2% | May 29, 2026 | The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of th... |
| CVE-2026-9493 | HIGH | 7.1 | 0.3% | May 29, 2026 | Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing... |
| CVE-2026-8732 | CRITICAL | 9.8 | 9.5% | May 29, 2026 | The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all ver... |
| CVE-2026-6324 | MEDIUM | 4.8 | 0.9% | May 29, 2026 | A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_in... |
| CVE-2026-6275 | MEDIUM | 6.4 | 0.3% | May 29, 2026 | The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers... |
| CVE-2026-2128 | MEDIUM | 5.3 | 0.3% | May 29, 2026 | The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versi... |
| CVE-2026-8995 | MEDIUM | 4.3 | 0.3% | May 29, 2026 | The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Information ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now