2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6447 | MEDIUM | 4.4 | 0.3% | May 2, 2026 | The Call for Price for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ... |
| CVE-2026-5113 | HIGH | 7.2 | 0.2% | May 2, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in v... |
| CVE-2026-5112 | HIGH | 7.2 | 0.2% | May 2, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to an... |
| CVE-2026-5111 | HIGH | 7.2 | 0.3% | May 2, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10... |
| CVE-2026-5110 | HIGH | 7.2 | 0.2% | May 2, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to an... |
| CVE-2026-5109 | HIGH | 7.2 | 0.2% | May 2, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10... |
| CVE-2026-7641 | HIGH | 8.8 | 0.7% | May 2, 2026 | The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up ... |
| CVE-2026-7604 | MEDIUM | 6.3 | 0.2% | May 2, 2026 | A vulnerability was identified in JeecgBoot up to 3.9.1. This affects the function OpenApiController.add/OpenApiControll... |
| CVE-2026-7603 | MEDIUM | 6.3 | 0.3% | May 2, 2026 | A vulnerability was determined in JeecgBoot up to 3.9.1. Affected by this issue is the function checkPathTraversalBatch ... |
| CVE-2026-7458 | CRITICAL | 9.8 | 0.6% | May 2, 2026 | The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, ... |
| CVE-2026-6963 | HIGH | 8.8 | 0.4% | May 2, 2026 | The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the w... |
| CVE-2026-6446 | MEDIUM | 5.4 | 0.2% | May 2, 2026 | The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all ... |
| CVE-2026-4882 | CRITICAL | 9.8 | 0.7% | May 2, 2026 | The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t... |
| CVE-2026-4658 | MEDIUM | 6.4 | 0.4% | May 2, 2026 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ... |
| CVE-2026-7638 | MEDIUM | 5.3 | 0.3% | May 2, 2026 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct O... |
| CVE-2026-7602 | MEDIUM | 6.3 | 0.2% | May 2, 2026 | A vulnerability was found in JeecgBoot up to 3.9.1. Affected by this vulnerability is an unknown functionality of the fi... |
| CVE-2026-7209 | MEDIUM | 6.4 | 0.2% | May 2, 2026 | The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-dire... |
| CVE-2026-6378 | MEDIUM | 6.4 | 0.2% | May 2, 2026 | The Maxi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `/wp-json/maxi-blocks/v1.0/sty... |
| CVE-2026-7601 | MEDIUM | 5.3 | 0.4% | May 2, 2026 | A vulnerability has been found in Open5GS up to 2.7.6. Affected is an unknown function of the file src/amf/gmm-handler.c... |
| CVE-2026-43824 | HIGH | 7.7 | 0.2% | May 2, 2026 | In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data. |
| CVE-2026-7600 | MEDIUM | 6.3 | 1.1% | May 2, 2026 | A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command ... |
| CVE-2026-7599 | MEDIUM | 6.3 | 0.3% | May 1, 2026 | A vulnerability was detected in Dayoooun hwpx-mcp 0.2.0. This affects the function save_document/export_to_text/export_t... |
| CVE-2026-7598 | HIGH | 7.3 | 0.5% | May 1, 2026 | A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_passwo... |
| CVE-2026-7597 | MEDIUM | 6.3 | 0.3% | May 1, 2026 | A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem... |
| CVE-2026-7596 | MEDIUM | 4.3 | 0.4% | May 1, 2026 | A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the functi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now