2026 CVE Vulnerabilities
48,876 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6672 | MEDIUM | 6.4 | 0.2% | May 6, 2026 | The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via s... |
| CVE-2026-6344 | MEDIUM | 4.9 | 0.6% | May 6, 2026 | The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This i... |
| CVE-2026-35254 | MEDIUM | 6.1 | 0.1% | May 6, 2026 | Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3... |
| CVE-2026-35253 | MEDIUM | 4.7 | 0.1% | May 6, 2026 | Vulnerability in the Oracle Macoron Tool product of Oracle Open Source Projects. The supported versions that is affected... |
| CVE-2026-23927 | MEDIUM | 5.1 | 0.2% | May 6, 2026 | A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead ... |
| CVE-2026-2306 | MEDIUM | 4.3 | 0.2% | May 6, 2026 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation du... |
| CVE-2026-5753 | MEDIUM | 6.5 | 0.3% | May 6, 2026 | The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions ... |
| CVE-2026-3208 | MEDIUM | 5.3 | 0.5% | May 6, 2026 | The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mis... |
| CVE-2026-7572 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor befor... |
| CVE-2026-40934 | MEDIUM | 6.8 | 0.3% | May 5, 2026 | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign auth... |
| CVE-2026-41950 | MEDIUM | 6.5 | 0.3% | May 5, 2026 | Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the fu... |
| CVE-2026-39402 | MEDIUM | 6.5 | 0.2% | May 5, 2026 | lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_l... |
| CVE-2026-35527 | MEDIUM | 5 | 0.3% | May 5, 2026 | Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues ... |
| CVE-2026-38947 | MEDIUM | 6.1 | 0.2% | May 5, 2026 | FluentCMS 1.2.3 is vulnerable to Cross Site Scripting (XSS) in TextHTML plugin. |
| CVE-2026-35453 | MEDIUM | 5.4 | 0.2% | May 5, 2026 | PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1... |
| CVE-2026-34527 | MEDIUM | 5.3 | 0.1% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniSe... |
| CVE-2026-33420 | MEDIUM | 5.3 | 0.2% | May 5, 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_det... |
| CVE-2026-32699 | MEDIUM | 5.3 | 0.3% | May 5, 2026 | FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fai... |
| CVE-2026-32603 | MEDIUM | 6.5 | 0.2% | May 5, 2026 | Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial... |
| CVE-2026-31893 | MEDIUM | 5.5 | 0.2% | May 5, 2026 | Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any ... |
| CVE-2026-31835 | MEDIUM | 5.4 | 0.2% | May 5, 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authenticatio... |
| CVE-2026-43002 | MEDIUM | 5.3 | 0.4% | May 5, 2026 | An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session stor... |
| CVE-2026-38432 | MEDIUM | 6.1 | 0.2% | May 5, 2026 | ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with ... |
| CVE-2026-7844 | MEDIUM | 6.3 | 0.3% | May 5, 2026 | A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function... |
| CVE-2026-6907 | MEDIUM | 5.3 | 0.4% | May 5, 2026 | An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erron... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now