2026 CVE Vulnerabilities
64,848 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43870 | HIGH | 7.3 | 0.4% | May 5, 2026 | Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutra... |
| CVE-2026-43868 | MEDIUM | 5.3 | 0.7% | May 5, 2026 | Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.... |
| CVE-2026-3601 | MEDIUM | 4.3 | 0.3% | May 5, 2026 | The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a miss... |
| CVE-2026-3359 | HIGH | 7.5 | 0.4% | May 5, 2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Inj... |
| CVE-2026-43869 | HIGH | 7.3 | 0.6% | May 5, 2026 | Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift:... |
| CVE-2026-7824 | MEDIUM | 5.9 | 0.2% | May 5, 2026 | An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is en... |
| CVE-2026-6418 | MEDIUM | 4.9 | 0.4% | May 5, 2026 | An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application... |
| CVE-2026-6180 | HIGH | 8.1 | 0.2% | May 5, 2026 | A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under spe... |
| CVE-2026-5192 | HIGH | 7.5 | 0.8% | May 5, 2026 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Trave... |
| CVE-2026-40797 | CRITICAL | 9.3 | 0.3% | May 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC We... |
| CVE-2026-3454 | MEDIUM | 6.5 | 0.5% | May 5, 2026 | The GenerateBlocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc... |
| CVE-2026-2729 | MEDIUM | 5.3 | 0.4% | May 5, 2026 | The Forminator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.52.0. ... |
| CVE-2026-7823 | CRITICAL | 9.8 | 1.8% | May 5, 2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of... |
| CVE-2026-7822 | MEDIUM | 6.3 | 0.2% | May 5, 2026 | A vulnerability was identified in itsourcecode Courier Management System 1.0. This impacts an unknown function of the fi... |
| CVE-2026-7812 | HIGH | 7.3 | 1.3% | May 5, 2026 | A vulnerability was found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The impacted element is the... |
| CVE-2026-7811 | HIGH | 7.3 | 0.4% | May 5, 2026 | A vulnerability has been found in 54yyyu code-mcp up to 4cfc4643541a110c906d93635b391bf7e357f4a8. The affected element i... |
| CVE-2026-4362 | MEDIUM | 6.5 | 0.4% | May 5, 2026 | The ElementsKit Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2026-7810 | HIGH | 7.3 | 0.4% | May 5, 2026 | A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the fu... |
| CVE-2026-5957 | MEDIUM | 6.5 | 0.6% | May 5, 2026 | The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This i... |
| CVE-2026-5294 | CRITICAL | 9.8 | 0.5% | May 5, 2026 | The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This ... |
| CVE-2026-5159 | MEDIUM | 6.4 | 0.3% | May 5, 2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed ... |
| CVE-2026-4803 | HIGH | 7.2 | 0.4% | May 5, 2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter ... |
| CVE-2026-4665 | MEDIUM | 6.4 | 0.3% | May 5, 2026 | The WP Carousel Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted fancybox `data-captio... |
| CVE-2026-3456 | HIGH | 7.5 | 0.3% | May 5, 2026 | The GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL... |
| CVE-2026-35228 | HIGH | 8.7 | 0.2% | May 5, 2026 | Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now