2026 CVE Vulnerabilities
48,244 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45841 | MEDIUM | 5.5 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix divide-by-zero in OSF... |
| CVE-2026-45840 | MEDIUM | 5.5 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: openvswitch: cap upcall PID array size and pre-size... |
| CVE-2026-45838 | MEDIUM | 5.5 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: fix end-of-list detection in cgroup_storage_ge... |
| CVE-2026-42751 | MEDIUM | 6.5 | 0.1% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking ... |
| CVE-2026-42750 | MEDIUM | 6.5 | 0.1% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nexcess WPComplete... |
| CVE-2026-42744 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded... |
| CVE-2026-42732 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded... |
| CVE-2026-42726 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Explo... |
| CVE-2026-42725 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout... |
| CVE-2026-3349 | MEDIUM | 6.1 | 0.3% | May 27, 2026 | The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter o... |
| CVE-2026-3348 | MEDIUM | 4.4 | 0.2% | May 27, 2026 | The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings (D... |
| CVE-2026-3012 | MEDIUM | 6.8 | 0.3% | May 27, 2026 | A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabl... |
| CVE-2026-2288 | MEDIUM | 4.8 | 0.2% | May 27, 2026 | The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all ... |
| CVE-2026-2280 | MEDIUM | 4.8 | 0.2% | May 27, 2026 | The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t... |
| CVE-2026-48968 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Master Slid... |
| CVE-2026-48877 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive... |
| CVE-2026-2237 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager ... |
| CVE-2026-8942 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2026-8906 | MEDIUM | 6.1 | 0.1% | May 27, 2026 | The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2026-8042 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo' shortcode attribut... |
| CVE-2026-7618 | MEDIUM | 4.9 | 0.3% | May 27, 2026 | The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection vi... |
| CVE-2026-49001 | MEDIUM | 5.3 | 0.1% | May 27, 2026 | Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cro... |
| CVE-2026-41704 | MEDIUM | 6.8 | 0.1% | May 27, 2026 | AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every re... |
| CVE-2026-41009 | MEDIUM | 5.8 | 0.1% | May 27, 2026 | When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient... |
| CVE-2026-40826 | MEDIUM | 6.9 | 0.3% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dsgvo_contracts view... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now