2026 CVE Vulnerabilities
48,075 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9798 | MEDIUM | 4.3 | 0.3% | May 28, 2026 | A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily... |
| CVE-2026-9673 | MEDIUM | 6.8 | 0.2% | May 28, 2026 | Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjec... |
| CVE-2026-9644 | MEDIUM | 6.4 | 0.2% | May 28, 2026 | The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2026-7533 | MEDIUM | 4.3 | 0.1% | May 28, 2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2026-3173 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i... |
| CVE-2026-9796 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check ... |
| CVE-2026-9794 | MEDIUM | 5.3 | 0.3% | May 28, 2026 | A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially cra... |
| CVE-2026-9792 | MEDIUM | 6.5 | 0.3% | May 28, 2026 | A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When cer... |
| CVE-2026-9791 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by acces... |
| CVE-2026-9241 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Thro... |
| CVE-2026-9228 | MEDIUM | 4.3 | 0.2% | May 28, 2026 | The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in ... |
| CVE-2026-5737 | MEDIUM | 6.5 | 0.4% | May 28, 2026 | The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and i... |
| CVE-2026-4888 | MEDIUM | 4.3 | 0.3% | May 28, 2026 | The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to... |
| CVE-2026-46544 | MEDIUM | 5.3 | 0.4% | May 27, 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Micro... |
| CVE-2026-46538 | MEDIUM | 5.9 | 0.2% | May 27, 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Micro... |
| CVE-2026-46416 | MEDIUM | 6.3 | 0.3% | May 27, 2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Micro... |
| CVE-2026-44720 | MEDIUM | 6.9 | 0.2% | May 27, 2026 | OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to 2.0.4, a critical authentication ... |
| CVE-2026-47270 | MEDIUM | 6.3 | 0.1% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb is a PAM modu... |
| CVE-2026-44710 | MEDIUM | 4.6 | 0.2% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/device.c passed t... |
| CVE-2026-21785 | MEDIUM | 4 | 0.1% | May 27, 2026 | A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlie... |
| CVE-2026-9759 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service |
| CVE-2026-48792 | MEDIUM | 4.4 | 0.1% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/evdev.c silently ... |
| CVE-2026-48066 | MEDIUM | 5.7 | 0.1% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/log.c contains a ... |
| CVE-2026-48065 | MEDIUM | 6.7 | 0.1% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/conf.c allocates ... |
| CVE-2026-47274 | MEDIUM | 6.3 | 0.1% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, multiple pam_usb help... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now