2026 CVE Vulnerabilities
64,659 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8679 | HIGH | 7.5 | 1.5% | May 22, 2026 | The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including... |
| CVE-2026-8381 | MEDIUM | 5.4 | 0.1% | May 22, 2026 | A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain bac... |
| CVE-2026-7798 | MEDIUM | 5.4 | 0.6% | May 22, 2026 | The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin f... |
| CVE-2026-7636 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Informat... |
| CVE-2026-7615 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2026-5072 | MEDIUM | 6.5 | 0.2% | May 22, 2026 | A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker to cause undefined behavior and potenti... |
| CVE-2026-9104 | MEDIUM | 6.4 | 0.2% | May 22, 2026 | The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up... |
| CVE-2026-9018 | HIGH | 8.8 | 0.5% | May 22, 2026 | The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation ... |
| CVE-2026-7509 | MEDIUM | 6.4 | 0.2% | May 22, 2026 | The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `the-subtitle` short... |
| CVE-2026-7249 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability c... |
| CVE-2026-6864 | MEDIUM | 6.1 | 0.3% | May 22, 2026 | The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' param... |
| CVE-2026-4070 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2026-44409 | HIGH | 7.5 | 0.2% | May 22, 2026 | There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control m... |
| CVE-2026-3481 | MEDIUM | 6.1 | 0.2% | May 22, 2026 | The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in al... |
| CVE-2026-2518 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing ca... |
| CVE-2026-9054 | CRITICAL | 9.2 | 0.3% | May 22, 2026 | An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel p... |
| CVE-2026-9053 | MEDIUM | 6.9 | 0.3% | May 22, 2026 | Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website wi... |
| CVE-2026-4834 | HIGH | 7.5 | 0.3% | May 22, 2026 | The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to,... |
| CVE-2026-46598 | MEDIUM | 5.3 | 0.3% | May 22, 2026 | For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when ... |
| CVE-2026-46597 | HIGH | 7.5 | 0.4% | May 22, 2026 | An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafte... |
| CVE-2026-46595 | CRITICAL | 10 | 0.5% | May 22, 2026 | Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of cal... |
| CVE-2026-42508 | CRITICAL | 9.1 | 7.3% | May 22, 2026 | Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and... |
| CVE-2026-39835 | MEDIUM | 5.3 | 0.5% | May 22, 2026 | SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be c... |
| CVE-2026-39834 | CRITICAL | 9.1 | 0.5% | May 22, 2026 | When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload ... |
| CVE-2026-39833 | CRITICAL | 9.1 | 0.4% | May 22, 2026 | The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enf... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now