2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7669 | MEDIUM | 6.3 | 0.4% | May 2, 2026 | A vulnerability was detected in sgl-project SGLang up to 0.5.9. Impacted is the function get_tokenizer of the file pytho... |
| CVE-2026-7668 | HIGH | 7.3 | 0.3% | May 2, 2026 | A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in ... |
| CVE-2026-7653 | MEDIUM | 6.3 | 1.3% | May 2, 2026 | A security flaw has been discovered in r-huijts mcp-server-rijksmuseum up to 1.0.4. Affected is the function open_image_... |
| CVE-2026-7645 | MEDIUM | 6.5 | 0.5% | May 2, 2026 | A vulnerability was found in ruvnet sublinear-time-solver 1.5.0. Affected by this vulnerability is the function export_s... |
| CVE-2026-7644 | HIGH | 7.3 | 0.3% | May 2, 2026 | A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the fil... |
| CVE-2026-7643 | MEDIUM | 4.3 | 0.2% | May 2, 2026 | A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of t... |
| CVE-2026-7642 | MEDIUM | 6.3 | 1.3% | May 2, 2026 | A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of th... |
| CVE-2026-7633 | MEDIUM | 6.5 | 0.3% | May 2, 2026 | A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the... |
| CVE-2026-7632 | HIGH | 7.3 | 0.3% | May 2, 2026 | A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function ... |
| CVE-2026-7631 | MEDIUM | 5.4 | 0.2% | May 2, 2026 | A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown fun... |
| CVE-2026-7630 | HIGH | 7.3 | 0.4% | May 2, 2026 | A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallService... |
| CVE-2026-7629 | MEDIUM | 6.3 | 1.1% | May 2, 2026 | A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of t... |
| CVE-2026-3504 | MEDIUM | 5.3 | 0.3% | May 2, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Infor... |
| CVE-2026-2554 | HIGH | 8.1 | 0.3% | May 2, 2026 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is... |
| CVE-2026-0703 | MEDIUM | 6.4 | 0.2% | May 2, 2026 | The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2026-7628 | MEDIUM | 6.3 | 1.1% | May 2, 2026 | A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function execu... |
| CVE-2026-6817 | MEDIUM | 5.8 | 0.2% | May 2, 2026 | The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter ... |
| CVE-2026-6525 | MEDIUM | 5.5 | 0.2% | May 2, 2026 | IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 |
| CVE-2026-6320 | HIGH | 7.5 | 0.4% | May 2, 2026 | The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and... |
| CVE-2026-4790 | MEDIUM | 5.4 | 0.2% | May 2, 2026 | The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored C... |
| CVE-2026-4100 | HIGH | 7.1 | 0.2% | May 2, 2026 | The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhoo... |
| CVE-2026-4062 | HIGH | 7.5 | 0.3% | May 2, 2026 | The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_i... |
| CVE-2026-4061 | HIGH | 7.5 | 0.3% | May 2, 2026 | The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all v... |
| CVE-2026-4060 | HIGH | 7.5 | 0.3% | May 2, 2026 | The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions u... |
| CVE-2026-7627 | MEDIUM | 6.3 | 0.3% | May 2, 2026 | A security vulnerability has been detected in 8nite metatrader-4-mcp 1.0.0. This vulnerability affects the function Call... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now