2026 CVE Vulnerabilities
64,618 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27398 | MEDIUM | 5.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Acces... |
| CVE-2026-27357 | MEDIUM | 5.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access C... |
| CVE-2026-27346 | MEDIUM | 4.9 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2026-24592 | MEDIUM | 5.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Acce... |
| CVE-2026-24586 | MEDIUM | 5.4 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incorrectly Configured Access Control Securit... |
| CVE-2026-24582 | MEDIUM | 4.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security... |
| CVE-2026-24554 | MEDIUM | 4.3 | 0.1% | May 25, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Convers Lab WPSubscription allows Cross Site Request Forgery. This i... |
| CVE-2026-24527 | MEDIUM | 4.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows... |
| CVE-2026-9503 | LOW | 3.3 | 0.1% | May 25, 2026 | A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file sr... |
| CVE-2026-9502 | MEDIUM | 5.3 | 0.2% | May 25, 2026 | A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the fil... |
| CVE-2026-9501 | LOW | 3.3 | 0.1% | May 25, 2026 | A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section... |
| CVE-2026-9500 | MEDIUM | 5.3 | 0.1% | May 25, 2026 | A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section ... |
| CVE-2026-48852 | LOW | 3.7 | 0.3% | May 25, 2026 | PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification. |
| CVE-2026-48851 | LOW | 3.1 | 0.2% | May 25, 2026 | PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not c... |
| CVE-2026-48850 | MEDIUM | 5.9 | 0.3% | May 25, 2026 | PuTTY 0.72 before 0.84 has a double free in RSA KEX. |
| CVE-2026-48589 | MEDIUM | 5.4 | 0.4% | May 25, 2026 | Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In ... |
| CVE-2026-44598 | MEDIUM | 5.4 | 0.4% | May 25, 2026 | With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vu... |
| CVE-2026-43828 | MEDIUM | 6.5 | 0.3% | May 25, 2026 | Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue... |
| CVE-2026-43827 | MEDIUM | 6.5 | 0.4% | May 25, 2026 | Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 ... |
| CVE-2026-24597 | MEDIUM | 4.3 | 0.1% | May 25, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery. This ... |
| CVE-2026-24574 | MEDIUM | 6.5 | 0.1% | May 25, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Fo... |
| CVE-2026-24545 | MEDIUM | 4.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2026-9498 | MEDIUM | 6.3 | 0.3% | May 25, 2026 | A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass ... |
| CVE-2026-9497 | MEDIUM | 6.3 | 0.3% | May 25, 2026 | A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject ... |
| CVE-2026-9486 | MEDIUM | 4.3 | 0.2% | May 25, 2026 | A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now