2026 CVE Vulnerabilities
64,616 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40826 | MEDIUM | 6.9 | 0.3% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dsgvo_contracts view... |
| CVE-2026-40825 | HIGH | 7 | 0.2% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view d... |
| CVE-2026-40824 | HIGH | 7 | 0.2% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view u... |
| CVE-2026-40823 | HIGH | 7 | 0.2% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct... |
| CVE-2026-40822 | MEDIUM | 6.9 | 0.3% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct... |
| CVE-2026-40821 | MEDIUM | 6.9 | 0.3% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountByID funct... |
| CVE-2026-40819 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task du... |
| CVE-2026-40818 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24confi_getDevic... |
| CVE-2026-40817 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAlarmProfiles fu... |
| CVE-2026-40816 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the mb24alarm.php files... |
| CVE-2026-40815 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24api_getUserAcc... |
| CVE-2026-40814 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dataapi.php files _... |
| CVE-2026-40813 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues funct... |
| CVE-2026-40812 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues funct... |
| CVE-2026-40811 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractservice ... |
| CVE-2026-40810 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endpoint d... |
| CVE-2026-3897 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_a... |
| CVE-2026-3896 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_aj... |
| CVE-2026-3895 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `... |
| CVE-2026-3375 | HIGH | 7.2 | 0.4% | May 27, 2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/noti... |
| CVE-2026-3279 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2026-3001 | MEDIUM | 6.1 | 0.2% | May 27, 2026 | The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all version... |
| CVE-2026-2030 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `... |
| CVE-2026-9200 | HIGH | 7.5 | 0.5% | May 27, 2026 | The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2... |
| CVE-2026-9014 | MEDIUM | 5.3 | 0.3% | May 27, 2026 | The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now