2026 CVE Vulnerabilities
48,334 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44608 | MEDIUM | 5.9 | 0.3% | May 20, 2026 | NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain... |
| CVE-2026-44390 | MEDIUM | 5.3 | 0.6% | May 20, 2026 | NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets t... |
| CVE-2026-42923 | MEDIUM | 5.3 | 0.3% | May 20, 2026 | NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to... |
| CVE-2026-42534 | MEDIUM | 5.3 | 0.5% | May 20, 2026 | NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purp... |
| CVE-2026-35070 | MEDIUM | 6.7 | 0.5% | May 20, 2026 | Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used... |
| CVE-2026-32792 | MEDIUM | 5.3 | 0.3% | May 20, 2026 | NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNS... |
| CVE-2026-6405 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) ... |
| CVE-2026-7385 | MEDIUM | 5.8 | 0.3% | May 20, 2026 | The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post au... |
| CVE-2026-6566 | MEDIUM | 4.3 | 0.3% | May 20, 2026 | The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Insecure Direct ... |
| CVE-2026-5776 | MEDIUM | 6.1 | 0.2% | May 20, 2026 | The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unau... |
| CVE-2026-44392 | MEDIUM | 5.3 | 0.2% | May 20, 2026 | Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator ... |
| CVE-2026-2955 | MEDIUM | 6.4 | 0.2% | May 20, 2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '... |
| CVE-2026-9056 | MEDIUM | 5.4 | 0.2% | May 20, 2026 | A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permiss... |
| CVE-2026-5075 | MEDIUM | 4.3 | 0.3% | May 20, 2026 | The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized ... |
| CVE-2026-8685 | MEDIUM | 6.5 | 0.4% | May 20, 2026 | The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all ... |
| CVE-2026-8627 | MEDIUM | 6.1 | 0.2% | May 20, 2026 | The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] var... |
| CVE-2026-8626 | MEDIUM | 6.1 | 0.3% | May 20, 2026 | The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all version... |
| CVE-2026-8624 | MEDIUM | 6.1 | 0.3% | May 20, 2026 | The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Param... |
| CVE-2026-8610 | MEDIUM | 4.3 | 0.3% | May 20, 2026 | The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and... |
| CVE-2026-8424 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2026-8423 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2026-8420 | MEDIUM | 6.1 | 0.2% | May 20, 2026 | The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2026-8419 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2026-8418 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2... |
| CVE-2026-8038 | MEDIUM | 6.4 | 0.2% | May 20, 2026 | The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now