2026 CVE Vulnerabilities
48,935 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7643 | MEDIUM | 4.3 | 0.2% | May 2, 2026 | A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.1. This impacts an unknown function of the file Next.js of t... |
| CVE-2026-7642 | MEDIUM | 6.3 | 1.3% | May 2, 2026 | A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of th... |
| CVE-2026-7633 | MEDIUM | 6.5 | 0.3% | May 2, 2026 | A vulnerability was identified in Totolink N300RH 6.1c.1353_B20190305. This impacts the function setUploadSetting of the... |
| CVE-2026-7631 | MEDIUM | 5.4 | 0.2% | May 2, 2026 | A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown fun... |
| CVE-2026-7629 | MEDIUM | 6.3 | 1.1% | May 2, 2026 | A flaw has been found in kleneway awesome-cursor-mpc-server up to 2.0.1. Impacted is the function runCodeReviewTool of t... |
| CVE-2026-3504 | MEDIUM | 5.3 | 0.3% | May 2, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Sensitive Infor... |
| CVE-2026-0703 | MEDIUM | 6.4 | 0.2% | May 2, 2026 | The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2026-7628 | MEDIUM | 6.3 | 1.1% | May 2, 2026 | A vulnerability was detected in crazyrabbitLTC mcp-code-review-server up to 0.1.0. This issue affects the function execu... |
| CVE-2026-6817 | MEDIUM | 5.8 | 0.2% | May 2, 2026 | The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter ... |
| CVE-2026-6525 | MEDIUM | 5.5 | 0.2% | May 2, 2026 | IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 |
| CVE-2026-4790 | MEDIUM | 5.4 | 0.2% | May 2, 2026 | The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored C... |
| CVE-2026-7627 | MEDIUM | 6.3 | 0.3% | May 2, 2026 | A security vulnerability has been detected in 8nite metatrader-4-mcp 1.0.0. This vulnerability affects the function Call... |
| CVE-2026-7612 | MEDIUM | 4.7 | 0.2% | May 2, 2026 | A vulnerability was determined in itsourcecode Courier Management System 1.0. Affected is an unknown function of the fil... |
| CVE-2026-5077 | MEDIUM | 5.4 | 0.2% | May 2, 2026 | The Total theme for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and includ... |
| CVE-2026-4024 | MEDIUM | 5.3 | 0.5% | May 2, 2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ... |
| CVE-2026-6457 | MEDIUM | 6.5 | 0.4% | May 2, 2026 | The Geo Mashup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geo_mashup_null_fields' par... |
| CVE-2026-6449 | MEDIUM | 5.3 | 0.5% | May 2, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Improper Authorization i... |
| CVE-2026-4650 | MEDIUM | 5.3 | 0.4% | May 2, 2026 | The FundPress – WordPress Donation Plugin for WordPress is vulnerable to authorization bypass in versions up to and incl... |
| CVE-2026-7605 | MEDIUM | 6.3 | 0.2% | May 2, 2026 | A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.u... |
| CVE-2026-43058 | MEDIUM | 5.5 | 0.1% | May 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: media: vidtv: fix pass-by-value structs causing MSA... |
| CVE-2026-6916 | MEDIUM | 6.4 | 0.4% | May 2, 2026 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul... |
| CVE-2026-6812 | MEDIUM | 4.4 | 0.3% | May 2, 2026 | The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via ... |
| CVE-2026-6447 | MEDIUM | 4.4 | 0.3% | May 2, 2026 | The Call for Price for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ... |
| CVE-2026-7604 | MEDIUM | 6.3 | 0.2% | May 2, 2026 | A vulnerability was identified in JeecgBoot up to 3.9.1. This affects the function OpenApiController.add/OpenApiControll... |
| CVE-2026-7603 | MEDIUM | 6.3 | 0.3% | May 2, 2026 | A vulnerability was determined in JeecgBoot up to 3.9.1. Affected by this issue is the function checkPathTraversalBatch ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now