2026 CVE Vulnerabilities
48,281 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4795 | MEDIUM | 6.5 | 0.2% | May 26, 2026 | A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware ... |
| CVE-2026-9515 | MEDIUM | 6.3 | 1.8% | May 26, 2026 | A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of t... |
| CVE-2026-9514 | MEDIUM | 6.3 | 1.8% | May 25, 2026 | A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. Impacted is the function setNetworkDiag of th... |
| CVE-2026-9513 | MEDIUM | 6.3 | 1.1% | May 25, 2026 | A weakness has been identified in Totolink CA750-PoE 6.2c.510. This issue affects the function NTPSyncWithHost of the fi... |
| CVE-2026-9512 | MEDIUM | 6.3 | 1.1% | May 25, 2026 | A security flaw has been discovered in Totolink CA750-PoE 6.2c.510. This vulnerability affects the function setPasswordC... |
| CVE-2026-45435 | MEDIUM | 6.5 | 0.2% | May 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activ... |
| CVE-2026-45217 | MEDIUM | 6.5 | 0.4% | May 25, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommer... |
| CVE-2026-42776 | MEDIUM | 6.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access C... |
| CVE-2026-42763 | MEDIUM | 6.5 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in SePay team SePay Gateway allows Retrieve Embedded Sensitive Data. This issue aff... |
| CVE-2026-32389 | MEDIUM | 5.4 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2026-9511 | MEDIUM | 6.3 | 1.1% | May 25, 2026 | A vulnerability was identified in Totolink CA750-PoE 6.2c.510. This affects the function setWebWlanIdx of the file /cgi-... |
| CVE-2026-27398 | MEDIUM | 5.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Acces... |
| CVE-2026-27357 | MEDIUM | 5.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access C... |
| CVE-2026-27346 | MEDIUM | 4.9 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2026-24592 | MEDIUM | 5.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Acce... |
| CVE-2026-24586 | MEDIUM | 5.4 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incorrectly Configured Access Control Securit... |
| CVE-2026-24582 | MEDIUM | 4.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in WPPOOL FlexTable allows Exploiting Incorrectly Configured Access Control Security... |
| CVE-2026-24554 | MEDIUM | 4.3 | 0.1% | May 25, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Convers Lab WPSubscription allows Cross Site Request Forgery. This i... |
| CVE-2026-24527 | MEDIUM | 4.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in Patterns in the cloud Autoship Cloud for WooCommerce Subscription Products allows... |
| CVE-2026-9502 | MEDIUM | 5.3 | 0.2% | May 25, 2026 | A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the fil... |
| CVE-2026-9500 | MEDIUM | 5.3 | 0.1% | May 25, 2026 | A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section ... |
| CVE-2026-48850 | MEDIUM | 5.9 | 0.3% | May 25, 2026 | PuTTY 0.72 before 0.84 has a double free in RSA KEX. |
| CVE-2026-48589 | MEDIUM | 5.4 | 0.4% | May 25, 2026 | Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In ... |
| CVE-2026-44598 | MEDIUM | 5.4 | 0.4% | May 25, 2026 | With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vu... |
| CVE-2026-43828 | MEDIUM | 6.5 | 0.3% | May 25, 2026 | Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now