2026 CVE Vulnerabilities
64,716 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7284 | CRITICAL | 9.8 | 0.5% | May 20, 2026 | The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation ... |
| CVE-2026-6555 | CRITICAL | 9.8 | 1.0% | May 20, 2026 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, ... |
| CVE-2026-6549 | MEDIUM | 6.4 | 0.2% | May 20, 2026 | The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute ... |
| CVE-2026-6456 | HIGH | 8.8 | 0.4% | May 20, 2026 | The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.... |
| CVE-2026-6452 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2026-6404 | MEDIUM | 4.4 | 0.2% | May 20, 2026 | The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2026-6401 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.1.... |
| CVE-2026-6400 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions... |
| CVE-2026-6399 | MEDIUM | 4.4 | 0.2% | May 20, 2026 | The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.... |
| CVE-2026-6397 | MEDIUM | 6.4 | 0.2% | May 20, 2026 | The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmorete... |
| CVE-2026-6395 | MEDIUM | 6.1 | 0.2% | May 20, 2026 | The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting ... |
| CVE-2026-6394 | MEDIUM | 5.4 | 0.3% | May 20, 2026 | The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server... |
| CVE-2026-6391 | MEDIUM | 6.1 | 0.2% | May 20, 2026 | The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in... |
| CVE-2026-6072 | MEDIUM | 6.5 | 0.5% | May 20, 2026 | The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through Us... |
| CVE-2026-5293 | MEDIUM | 6.4 | 0.3% | May 20, 2026 | The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js'... |
| CVE-2026-45232 | LOW | 3.7 | 0.3% | May 20, 2026 | Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connect... |
| CVE-2026-43620 | MEDIUM | 5.5 | 0.5% | May 20, 2026 | Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver... |
| CVE-2026-43619 | HIGH | 7.2 | 0.1% | May 20, 2026 | Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod,... |
| CVE-2026-43618 | HIGH | 8.1 | 0.8% | May 20, 2026 | Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit s... |
| CVE-2026-43617 | MEDIUM | 6.3 | 0.3% | May 20, 2026 | Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access ... |
| CVE-2026-3985 | HIGH | 7.5 | 0.4% | May 20, 2026 | The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection v... |
| CVE-2026-45585 | MEDIUM | 6.8 | 1.2% | May 20, 2026 | Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". ... |
| CVE-2026-39309 | MEDIUM | 5.5 | 0.2% | May 20, 2026 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas... |
| CVE-2026-35593 | MEDIUM | 6.8 | 0.6% | May 20, 2026 | Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowled... |
| CVE-2026-34970 | MEDIUM | 5.3 | 0.4% | May 20, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to acces... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now