2026 CVE Vulnerabilities
48,297 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8340 | MEDIUM | 4.3 | 0.1% | May 22, 2026 | Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents perm... |
| CVE-2026-8997 | MEDIUM | 4.8 | 0.1% | May 22, 2026 | vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json)... |
| CVE-2026-8672 | MEDIUM | 5.1 | 0.1% | May 22, 2026 | Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default User... |
| CVE-2026-44618 | MEDIUM | 5.3 | 0.3% | May 22, 2026 | Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users a... |
| CVE-2026-5755 | MEDIUM | 6.5 | 0.2% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to ... |
| CVE-2026-4646 | MEDIUM | 4.3 | 0.3% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supp... |
| CVE-2026-4635 | MEDIUM | 5.3 | 0.2% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channe... |
| CVE-2026-3636 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team memb... |
| CVE-2026-25607 | MEDIUM | 5.7 | 0.1% | May 22, 2026 | Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzin... |
| CVE-2026-8692 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to... |
| CVE-2026-8684 | MEDIUM | 5.3 | 0.3% | May 22, 2026 | The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includ... |
| CVE-2026-8381 | MEDIUM | 5.4 | 0.1% | May 22, 2026 | A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain bac... |
| CVE-2026-7798 | MEDIUM | 5.4 | 0.6% | May 22, 2026 | The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin f... |
| CVE-2026-7636 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Informat... |
| CVE-2026-7615 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2026-5072 | MEDIUM | 6.5 | 0.2% | May 22, 2026 | A bitwise shift vulnerability in Zephyr's PTP subsystem allows a remote attacker to cause undefined behavior and potenti... |
| CVE-2026-9104 | MEDIUM | 6.4 | 0.2% | May 22, 2026 | The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up... |
| CVE-2026-7509 | MEDIUM | 6.4 | 0.2% | May 22, 2026 | The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `the-subtitle` short... |
| CVE-2026-7249 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability c... |
| CVE-2026-6864 | MEDIUM | 6.1 | 0.3% | May 22, 2026 | The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' param... |
| CVE-2026-4070 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2026-3481 | MEDIUM | 6.1 | 0.2% | May 22, 2026 | The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in al... |
| CVE-2026-2518 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing ca... |
| CVE-2026-9053 | MEDIUM | 6.9 | 0.3% | May 22, 2026 | Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website wi... |
| CVE-2026-46598 | MEDIUM | 5.3 | 0.3% | May 22, 2026 | For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now