2026 CVE Vulnerabilities
64,705 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6566 | MEDIUM | 4.3 | 0.3% | May 20, 2026 | The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct ... |
| CVE-2026-5776 | MEDIUM | 6.1 | 0.2% | May 20, 2026 | The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unau... |
| CVE-2026-47784 | HIGH | 8.1 | 0.5% | May 20, 2026 | In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because me... |
| CVE-2026-47783 | HIGH | 8.1 | 1.3% | May 20, 2026 | In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a ... |
| CVE-2026-44392 | MEDIUM | 5.3 | 0.2% | May 20, 2026 | Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator ... |
| CVE-2026-2955 | MEDIUM | 6.4 | 0.2% | May 20, 2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '... |
| CVE-2026-9057 | HIGH | 8.2 | 0.3% | May 20, 2026 | A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” pe... |
| CVE-2026-9056 | MEDIUM | 5.4 | 0.2% | May 20, 2026 | A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permiss... |
| CVE-2026-7522 | HIGH | 8.8 | 0.8% | May 20, 2026 | The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an... |
| CVE-2026-5075 | MEDIUM | 4.3 | 0.3% | May 20, 2026 | The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized ... |
| CVE-2026-9010 | HIGH | 7.5 | 0.4% | May 20, 2026 | The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameter... |
| CVE-2026-9003 | HIGH | 8.7 | 0.5% | May 20, 2026 | E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauthenticated remote att... |
| CVE-2026-7637 | CRITICAL | 9.8 | 0.6% | May 20, 2026 | The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deseria... |
| CVE-2026-7460 | HIGH | 7.4 | 0.3% | May 20, 2026 | mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Ma... |
| CVE-2026-24215 | HIGH | 7.5 | 0.4% | May 20, 2026 | NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled ... |
| CVE-2026-24214 | CRITICAL | 9.8 | 0.7% | May 20, 2026 | NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer ove... |
| CVE-2026-24213 | CRITICAL | 9.8 | 0.7% | May 20, 2026 | NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-boun... |
| CVE-2026-24210 | HIGH | 7.5 | 0.6% | May 20, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful ... |
| CVE-2026-24209 | HIGH | 7.5 | 0.7% | May 20, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successf... |
| CVE-2026-24208 | HIGH | 7.5 | 0.7% | May 20, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successf... |
| CVE-2026-24207 | CRITICAL | 9.8 | 2.2% | May 20, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes... |
| CVE-2026-24206 | CRITICAL | 9.8 | 0.5% | May 20, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes... |
| CVE-2026-24163 | CRITICAL | 9.8 | 0.6% | May 20, 2026 | NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deseri... |
| CVE-2026-24160 | HIGH | 7.5 | 0.5% | May 20, 2026 | NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a n... |
| CVE-2026-24142 | CRITICAL | 9.8 | 0.4% | May 20, 2026 | NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful ex... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now