2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7612 | MEDIUM | 4.7 | 0.2% | May 2, 2026 | A vulnerability was determined in itsourcecode Courier Management System 1.0. Affected is an unknown function of the fil... |
| CVE-2026-7611 | HIGH | 8.1 | 0.2% | May 2, 2026 | A vulnerability was found in TRENDnet TEW-821DAP up to 1.12B01. This impacts the function platform_do_upgrade_cameo_dev ... |
| CVE-2026-7610 | HIGH | 8.1 | 0.3% | May 2, 2026 | A vulnerability has been found in TRENDnet TEW-821DAP 1.12B01. This affects an unknown function of the file /www/cgi/ssi... |
| CVE-2026-7609 | HIGH | 8.8 | 4.1% | May 2, 2026 | A flaw has been found in TRENDnet TEW-821DAP up to 1.12B01. The impacted element is the function tools_diagnostic of the... |
| CVE-2026-7491 | HIGH | 8.6 | 0.3% | May 2, 2026 | School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote att... |
| CVE-2026-7490 | HIGH | 7.2 | 0.5% | May 2, 2026 | CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to up... |
| CVE-2026-7489 | HIGH | 8.8 | 0.3% | May 2, 2026 | CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary ... |
| CVE-2026-5077 | MEDIUM | 5.4 | 0.2% | May 2, 2026 | The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and includ... |
| CVE-2026-7608 | HIGH | 8 | 5.2% | May 2, 2026 | A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic... |
| CVE-2026-5324 | HIGH | 7.2 | 0.4% | May 2, 2026 | The Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versio... |
| CVE-2026-4024 | MEDIUM | 5.3 | 0.5% | May 2, 2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ... |
| CVE-2026-7649 | HIGH | 7.5 | 0.3% | May 2, 2026 | The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is... |
| CVE-2026-7607 | HIGH | 8.8 | 0.6% | May 2, 2026 | A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function auto_update_firmware... |
| CVE-2026-7606 | HIGH | 8.1 | 0.2% | May 2, 2026 | A weakness has been identified in TRENDnet TEW-821DAP 1.12B01. This issue affects the function find_hwid/new_gui_update_... |
| CVE-2026-6457 | MEDIUM | 6.5 | 0.4% | May 2, 2026 | The Geo Mashup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geo_mashup_null_fields' par... |
| CVE-2026-6449 | MEDIUM | 5.3 | 0.5% | May 2, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization i... |
| CVE-2026-6229 | HIGH | 7.2 | 0.4% | May 2, 2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and incl... |
| CVE-2026-4650 | MEDIUM | 5.3 | 0.4% | May 2, 2026 | The FundPress – WordPress Donation Plugin for WordPress is vulnerable to authorization bypass in versions up to and incl... |
| CVE-2026-2052 | HIGH | 8.8 | 0.8% | May 2, 2026 | The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vuln... |
| CVE-2026-7605 | MEDIUM | 6.3 | 0.2% | May 2, 2026 | A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.u... |
| CVE-2026-43058 | MEDIUM | 5.5 | 0.1% | May 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix pass-by-value structs causing MSA... |
| CVE-2026-7647 | HIGH | 8.1 | 0.5% | May 2, 2026 | The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3... |
| CVE-2026-7049 | HIGH | 7.2 | 0.6% | May 2, 2026 | The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery... |
| CVE-2026-6916 | MEDIUM | 6.4 | 0.4% | May 2, 2026 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul... |
| CVE-2026-6812 | MEDIUM | 4.4 | 0.3% | May 2, 2026 | The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now