2026 CVE Vulnerabilities
64,848 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2948 | MEDIUM | 6.4 | 0.2% | May 5, 2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Server-Side Requ... |
| CVE-2026-6704 | MEDIUM | 6.1 | 0.2% | May 5, 2026 | The Blog Settings plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all v... |
| CVE-2026-6702 | MEDIUM | 6.1 | 0.1% | May 5, 2026 | The Publish 2 Ping.fm plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2026-6701 | MEDIUM | 4.3 | 0.2% | May 5, 2026 | The addfreespace plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2026-6700 | MEDIUM | 4.3 | 0.1% | May 5, 2026 | The DX Sources plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.... |
| CVE-2026-6696 | MEDIUM | 6.1 | 0.2% | May 5, 2026 | The Zingaya Click-to-Call plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email', 'first_n... |
| CVE-2026-6255 | MEDIUM | 6.4 | 0.2% | May 5, 2026 | The Simple Owl Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'num' attribute of t... |
| CVE-2026-5505 | MEDIUM | 6.4 | 0.2% | May 5, 2026 | The WP-Clippy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `clippy` shortcode in a... |
| CVE-2026-5247 | MEDIUM | 5.5 | 0.3% | May 5, 2026 | The Schedule Post Changes With PublishPress Future plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2026-5100 | HIGH | 7.5 | 0.4% | May 5, 2026 | The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versio... |
| CVE-2026-4730 | MEDIUM | 6.4 | 0.2% | May 5, 2026 | The Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website plugin for WordPress is vulnerabl... |
| CVE-2026-4409 | MEDIUM | 6.5 | 0.2% | May 5, 2026 | The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leak... |
| CVE-2026-2868 | MEDIUM | 6.4 | 0.2% | May 5, 2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Sit... |
| CVE-2026-1921 | MEDIUM | 4.9 | 0.6% | May 5, 2026 | The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.8.2 via ... |
| CVE-2026-5722 | CRITICAL | 9.8 | 0.5% | May 5, 2026 | The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.... |
| CVE-2026-44029 | MEDIUM | 5.3 | 0.6% | May 5, 2026 | An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "n... |
| CVE-2026-44028 | HIGH | 7.5 | 0.2% | May 5, 2026 | An issue was discovered in Nix before 2.34.7 and Lix before 2.95.2. Unbounded recursion in the NAR (Nix Archive) parser ... |
| CVE-2026-7788 | HIGH | 7.3 | 0.4% | May 5, 2026 | A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. The af... |
| CVE-2026-7785 | HIGH | 7.3 | 1.3% | May 5, 2026 | A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f2... |
| CVE-2026-7784 | HIGH | 7.3 | 0.5% | May 5, 2026 | A vulnerability has been found in RTGS2017 NagaAgent up to 5.1.0. This issue affects some unknown processing of the file... |
| CVE-2026-7783 | MEDIUM | 6.3 | 0.2% | May 5, 2026 | A flaw has been found in CodeCanyon Perfex CRM up to 3.4.1. This vulnerability affects the function AbstractKanban::appl... |
| CVE-2026-7782 | MEDIUM | 6.3 | 0.2% | May 4, 2026 | A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the fil... |
| CVE-2026-7781 | MEDIUM | 4.3 | 0.3% | May 4, 2026 | A security vulnerability has been detected in Open5GS up to 2.7.7. Affected by this issue is the function udm_nudm_uecm_... |
| CVE-2026-7791 | HIGH | 8.5 | 0.1% | May 4, 2026 | Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpace... |
| CVE-2026-7780 | MEDIUM | 4.3 | 0.3% | May 4, 2026 | A weakness has been identified in Open5GS up to 2.7.7. Affected by this vulnerability is the function udm_state_operatio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now