2026 CVE Vulnerabilities
48,096 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-38931 | MEDIUM | 5.4 | 0.2% | May 27, 2026 | A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp ... |
| CVE-2026-38930 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component... |
| CVE-2026-9674 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows atta... |
| CVE-2026-6957 | MEDIUM | 4.9 | 0.3% | May 27, 2026 | Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to constr... |
| CVE-2026-49102 | MEDIUM | 6.1 | 0.2% | May 27, 2026 | Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes compo... |
| CVE-2026-49059 | MEDIUM | 4.7 | 0.2% | May 27, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. ... |
| CVE-2026-49053 | MEDIUM | 5.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ... |
| CVE-2026-49052 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ... |
| CVE-2026-49051 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured... |
| CVE-2026-49047 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Securit... |
| CVE-2026-49045 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2026-49044 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advan... |
| CVE-2026-48973 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Secu... |
| CVE-2026-48927 | MEDIUM | 5.5 | 0.2% | May 27, 2026 | Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting... |
| CVE-2026-48926 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allow... |
| CVE-2026-48925 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attacker... |
| CVE-2026-48924 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to pe... |
| CVE-2026-48923 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation... |
| CVE-2026-48919 | MEDIUM | 6.6 | 0.3% | May 27, 2026 | Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. |
| CVE-2026-48918 | MEDIUM | 6.6 | 0.2% | May 27, 2026 | Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default. |
| CVE-2026-48917 | MEDIUM | 6.6 | 0.3% | May 27, 2026 | Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation. |
| CVE-2026-48916 | MEDIUM | 6.6 | 0.3% | May 27, 2026 | Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals. |
| CVE-2026-48545 | MEDIUM | 6.8 | 0.4% | May 27, 2026 | Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Spa... |
| CVE-2026-47119 | MEDIUM | 6.1 | 0.2% | May 27, 2026 | Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arb... |
| CVE-2026-45571 | MEDIUM | 5.4 | 0.3% | May 27, 2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now