2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6415 | MEDIUM | 6.4 | 0.3% | May 15, 2026 | The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u... |
| CVE-2026-6403 | HIGH | 7.5 | 0.8% | May 15, 2026 | The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is... |
| CVE-2026-6228 | HIGH | 8.8 | 0.3% | May 15, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and includ... |
| CVE-2026-5229 | CRITICAL | 9.8 | 0.7% | May 15, 2026 | The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This... |
| CVE-2026-4683 | MEDIUM | 6.5 | 0.3% | May 15, 2026 | The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2026-44088 | HIGH | 8.6 | 0.4% | May 15, 2026 | SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of t... |
| CVE-2026-8654 | HIGH | 8.7 | 0.2% | May 15, 2026 | Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operat... |
| CVE-2026-6646 | MEDIUM | 6.4 | 0.3% | May 15, 2026 | The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all v... |
| CVE-2026-4094 | HIGH | 8.1 | 0.3% | May 15, 2026 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss du... |
| CVE-2026-41702 | HIGH | 7 | 0.1% | May 15, 2026 | VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a... |
| CVE-2026-43490 | HIGH | 8.8 | 0.4% | May 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inher... |
| CVE-2026-28761 | HIGH | 8.5 | 0.1% | May 15, 2026 | Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 a... |
| CVE-2026-24662 | MEDIUM | 5.4 | 0.1% | May 15, 2026 | Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and ear... |
| CVE-2026-0481 | CRITICAL | 9.2 | 0.3% | May 15, 2026 | Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to per... |
| CVE-2026-7373 | HIGH | 8.5 | 0.2% | May 15, 2026 | Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level contr... |
| CVE-2026-2652 | HIGH | 8.6 | 1.5% | May 15, 2026 | A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when... |
| CVE-2026-0428 | LOW | 1.8 | 0.1% | May 15, 2026 | Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_... |
| CVE-2026-0427 | MEDIUM | 4.6 | 0.1% | May 15, 2026 | Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virt... |
| CVE-2026-8612 | MEDIUM | 5.3 | 0.1% | May 15, 2026 | WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cac... |
| CVE-2026-0438 | MEDIUM | 5.4 | 0.1% | May 15, 2026 | A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly pri... |
| CVE-2026-0432 | HIGH | 8.5 | 0.1% | May 15, 2026 | Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achiev... |
| CVE-2026-6811 | HIGH | 7.5 | 0.4% | May 14, 2026 | Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSO... |
| CVE-2026-45248 | MEDIUM | 6.9 | 0.4% | May 14, 2026 | Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users e... |
| CVE-2026-44671 | HIGH | 7.5 | 0.5% | May 14, 2026 | ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was di... |
| CVE-2026-44428 | MEDIUM | 4.7 | 0.2% | May 14, 2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now