2026 CVE Vulnerabilities
64,616 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42757 | CRITICAL | 9.9 | 0.3% | May 27, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias... |
| CVE-2026-42756 | CRITICAL | 9.9 | 0.3% | May 27, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP ... |
| CVE-2026-42755 | CRITICAL | 9.3 | 0.2% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn... |
| CVE-2026-42754 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phbernard Favicon ... |
| CVE-2026-42753 | HIGH | 7.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly... |
| CVE-2026-42751 | MEDIUM | 6.5 | 0.1% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking ... |
| CVE-2026-42750 | MEDIUM | 6.5 | 0.1% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nexcess WPComplete... |
| CVE-2026-42749 | HIGH | 7.1 | 0.2% | May 27, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types ... |
| CVE-2026-42748 | CRITICAL | 9.9 | 0.3% | May 27, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web She... |
| CVE-2026-42747 | CRITICAL | 9.3 | 0.2% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Eas... |
| CVE-2026-42746 | HIGH | 7.3 | 0.2% | May 27, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in ZAYTECH Smart Online Order for Clover clover-online-o... |
| CVE-2026-42745 | HIGH | 7.3 | 0.2% | May 27, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online Order for Clover clover-o... |
| CVE-2026-42744 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded... |
| CVE-2026-42740 | CRITICAL | 9.3 | 0.2% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan ... |
| CVE-2026-42739 | HIGH | 7.1 | 0.1% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IniLerm Advanced I... |
| CVE-2026-42738 | HIGH | 7.1 | 0.1% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZAYTECH Smart Onli... |
| CVE-2026-42737 | HIGH | 8.6 | 0.3% | May 27, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hote... |
| CVE-2026-42736 | HIGH | 7.5 | 0.2% | May 27, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-better-messages allows ... |
| CVE-2026-42735 | HIGH | 8.2 | 0.3% | May 27, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-managem... |
| CVE-2026-42734 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Ma... |
| CVE-2026-42733 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 WPCS cu... |
| CVE-2026-42732 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded... |
| CVE-2026-42731 | CRITICAL | 9.8 | 0.3% | May 27, 2026 | Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allow... |
| CVE-2026-42730 | HIGH | 8.5 | 0.3% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStu... |
| CVE-2026-42729 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive Prop... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now