2026 CVE Vulnerabilities
48,611 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27421 | MEDIUM | 6.5 | 0.2% | May 7, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elem... |
| CVE-2026-27416 | MEDIUM | 5.3 | 0.2% | May 7, 2026 | Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2026-27329 | MEDIUM | 5.3 | 0.3% | May 7, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Wishlist allows Exploiting Incor... |
| CVE-2026-25468 | MEDIUM | 5.3 | 0.3% | May 7, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elem... |
| CVE-2026-25436 | MEDIUM | 5.3 | 0.2% | May 7, 2026 | Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Co... |
| CVE-2026-6214 | MEDIUM | 6.5 | 0.4% | May 7, 2026 | The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0.... |
| CVE-2026-42194 | MEDIUM | 6.8 | 0.2% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_m... |
| CVE-2026-41891 | MEDIUM | 5.3 | 0.3% | May 7, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-41890 | MEDIUM | 6.9 | 0.3% | May 7, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-41671 | MEDIUM | 6.8 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modu... |
| CVE-2026-41662 | MEDIUM | 5.2 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify wheth... |
| CVE-2026-41661 | MEDIUM | 6.1 | 0.2% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, an unauthenticated attacker can execute arbi... |
| CVE-2026-41658 | MEDIUM | 6.5 | 0.2% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio inventory module enforces author... |
| CVE-2026-41657 | MEDIUM | 4.9 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the contacts_data.php endpoint uses a weaker... |
| CVE-2026-41656 | MEDIUM | 4.5 | 0.4% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the add mode in modules/documents-files.php ... |
| CVE-2026-41655 | MEDIUM | 6.5 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the ecard_preview.php endpoint does not vali... |
| CVE-2026-41004 | MEDIUM | 4.4 | 0.2% | May 7, 2026 | When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Sp... |
| CVE-2026-4807 | MEDIUM | 6.5 | 0.5% | May 7, 2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and inclu... |
| CVE-2026-44600 | MEDIUM | 5.3 | 0.4% | May 7, 2026 | Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-202... |
| CVE-2026-44599 | MEDIUM | 5.3 | 0.3% | May 7, 2026 | Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008. |
| CVE-2026-6222 | MEDIUM | 5.3 | 0.4% | May 7, 2026 | The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.51.1.... |
| CVE-2026-40003 | MEDIUM | 6.8 | 0.3% | May 7, 2026 | ZTE ZX297520V3 BootROM contains a vulnerability that allows arbitrary memory writes via USB. Attackers can exploit the l... |
| CVE-2026-41484 | MEDIUM | 5.9 | 0.3% | May 6, 2026 | OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In ver... |
| CVE-2026-41483 | MEDIUM | 5.9 | 0.3% | May 6, 2026 | OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlie... |
| CVE-2026-41417 | MEDIUM | 5.3 | 0.3% | May 6, 2026 | Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created f... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now