2026 CVE Vulnerabilities
64,469 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9015 | MEDIUM | 4.3 | 0.3% | May 28, 2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl... |
| CVE-2026-8689 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in a... |
| CVE-2026-7526 | MEDIUM | 4.3 | 0.4% | May 28, 2026 | The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2026-7048 | MEDIUM | 6.5 | 0.5% | May 28, 2026 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL In... |
| CVE-2026-6937 | MEDIUM | 5.3 | 0.6% | May 28, 2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Mis... |
| CVE-2026-6226 | HIGH | 8.8 | 0.4% | May 28, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions ... |
| CVE-2026-4408 | CRITICAL | 9.8 | 2.5% | May 28, 2026 | A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain con... |
| CVE-2026-4334 | MEDIUM | 6.4 | 0.2% | May 28, 2026 | The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headline' parameter in th... |
| CVE-2026-9806 | MEDIUM | 6.3 | 0.3% | May 28, 2026 | A stored cross-site scripting (XSS) vulnerability exists in the notification panel of CTI Transmute in versions prior to... |
| CVE-2026-9618 | MEDIUM | 4.3 | 0.1% | May 28, 2026 | The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugin ... |
| CVE-2026-9227 | HIGH | 8.8 | 0.7% | May 28, 2026 | The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and i... |
| CVE-2026-8682 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | The 3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On plugin for WordPress is vulnerable to authorization... |
| CVE-2026-7862 | HIGH | 8.6 | 0.2% | May 28, 2026 | The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request... |
| CVE-2026-7797 | HIGH | 7.5 | 0.6% | May 28, 2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to tim... |
| CVE-2026-7660 | MEDIUM | 6.1 | 0.2% | May 28, 2026 | The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter ... |
| CVE-2026-7651 | MEDIUM | 5.3 | 0.4% | May 28, 2026 | The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U... |
| CVE-2026-7634 | HIGH | 7.2 | 0.4% | May 28, 2026 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in ... |
| CVE-2026-7621 | MEDIUM | 4.3 | 0.3% | May 28, 2026 | The SMTP2GO for WordPress – Email Made Easy plugin for WordPress is vulnerable to unauthorized access in all versions up... |
| CVE-2026-7552 | MEDIUM | 5.3 | 0.3% | May 28, 2026 | The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19.... |
| CVE-2026-7052 | HIGH | 7.2 | 0.3% | May 28, 2026 | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr... |
| CVE-2026-6455 | HIGH | 8.1 | 0.2% | May 28, 2026 | The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary F... |
| CVE-2026-6427 | MEDIUM | 6.4 | 0.3% | May 28, 2026 | The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,... |
| CVE-2026-44604 | HIGH | 7 | 0.6% | May 28, 2026 | A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive ... |
| CVE-2026-9803 | MEDIUM | 5.3 | 0.4% | May 28, 2026 | A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vuln... |
| CVE-2026-9802 | MEDIUM | 6.8 | 0.3% | May 28, 2026 | A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now