2026 CVE Vulnerabilities
48,530 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5243 | MEDIUM | 6.4 | 0.2% | May 14, 2026 | The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for Wor... |
| CVE-2026-4527 | MEDIUM | 6.5 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, an... |
| CVE-2026-4524 | MEDIUM | 6.5 | 0.3% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9.1 before 18.9.7, 18.10 before 18.10.6, a... |
| CVE-2026-3829 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is v... |
| CVE-2026-3607 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2026-3160 | MEDIUM | 5.8 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2026-3074 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2026-3073 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2026-1338 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7, 18.10 before 18.10.6, an... |
| CVE-2026-7648 | MEDIUM | 4.3 | 0.4% | May 14, 2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to payment b... |
| CVE-2026-7525 | MEDIUM | 4.3 | 0.3% | May 14, 2026 | The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to authorization bypass in all versions up... |
| CVE-2026-5361 | MEDIUM | 6.4 | 0.4% | May 14, 2026 | The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in versions u... |
| CVE-2026-5486 | MEDIUM | 6.5 | 0.5% | May 14, 2026 | The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' p... |
| CVE-2026-44919 | MEDIUM | 6.5 | 0.5% | May 14, 2026 | In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can oc... |
| CVE-2026-41281 | MEDIUM | 6.3 | 0.1% | May 14, 2026 | Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CW... |
| CVE-2026-44448 | MEDIUM | 6.5 | 0.1% | May 13, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints fa... |
| CVE-2026-44445 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restrict... |
| CVE-2026-44441 | MEDIUM | 4.3 | 0.2% | May 13, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user cou... |
| CVE-2026-44440 | MEDIUM | 5.7 | 0.4% | May 13, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitati... |
| CVE-2026-44437 | MEDIUM | 6.1 | 0.2% | May 13, 2026 | The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25,... |
| CVE-2026-44426 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/namespaces/:tenant returns the full namespace object — ... |
| CVE-2026-44425 | MEDIUM | 5.4 | 0.3% | May 13, 2026 | ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in ... |
| CVE-2026-44424 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/devices/:uid returns the full device object whenever th... |
| CVE-2026-44423 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/sessions/:uid returns the full session object for any a... |
| CVE-2026-44195 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now