2026 CVE Vulnerabilities
48,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2237 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager ... |
| CVE-2026-8942 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The MetaMagic SEO Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2026-8906 | MEDIUM | 6.1 | 0.1% | May 27, 2026 | The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2026-8042 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo' shortcode attribut... |
| CVE-2026-7618 | MEDIUM | 4.9 | 0.3% | May 27, 2026 | The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection vi... |
| CVE-2026-49001 | MEDIUM | 5.3 | 0.1% | May 27, 2026 | Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cro... |
| CVE-2026-41704 | MEDIUM | 6.8 | 0.1% | May 27, 2026 | AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every re... |
| CVE-2026-41009 | MEDIUM | 5.8 | 0.1% | May 27, 2026 | When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient... |
| CVE-2026-40826 | MEDIUM | 6.9 | 0.3% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dsgvo_contracts view... |
| CVE-2026-40822 | MEDIUM | 6.9 | 0.3% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct... |
| CVE-2026-40821 | MEDIUM | 6.9 | 0.3% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountByID funct... |
| CVE-2026-3897 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_a... |
| CVE-2026-3896 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_aj... |
| CVE-2026-3895 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `... |
| CVE-2026-3279 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2026-3001 | MEDIUM | 6.1 | 0.2% | May 27, 2026 | The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all version... |
| CVE-2026-2030 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `... |
| CVE-2026-9014 | MEDIUM | 5.3 | 0.3% | May 27, 2026 | The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2026-8943 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The GoStats for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2026-8941 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1... |
| CVE-2026-8939 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi... |
| CVE-2026-8938 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The auto making JSON-LD plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2026-8911 | MEDIUM | 6.1 | 0.1% | May 27, 2026 | The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2026-8903 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in al... |
| CVE-2026-8899 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Auto Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'thumbnails' shortcode in a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now