2026 CVE Vulnerabilities
48,942 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6447 | MEDIUM | 4.4 | 0.3% | May 2, 2026 | The Call for Price for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ... |
| CVE-2026-7604 | MEDIUM | 6.3 | 0.2% | May 2, 2026 | A vulnerability was identified in JeecgBoot up to 3.9.1. This affects the function OpenApiController.add/OpenApiControll... |
| CVE-2026-7603 | MEDIUM | 6.3 | 0.3% | May 2, 2026 | A vulnerability was determined in JeecgBoot up to 3.9.1. Affected by this issue is the function checkPathTraversalBatch ... |
| CVE-2026-6446 | MEDIUM | 5.4 | 0.2% | May 2, 2026 | The My Social Feeds – Social Feeds Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all ... |
| CVE-2026-4658 | MEDIUM | 6.4 | 0.4% | May 2, 2026 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ... |
| CVE-2026-7638 | MEDIUM | 5.3 | 0.3% | May 2, 2026 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Insecure Direct O... |
| CVE-2026-7602 | MEDIUM | 6.3 | 0.2% | May 2, 2026 | A vulnerability was found in JeecgBoot up to 3.9.1. Affected by this vulnerability is an unknown functionality of the fi... |
| CVE-2026-7209 | MEDIUM | 6.4 | 0.2% | May 2, 2026 | The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-dire... |
| CVE-2026-6378 | MEDIUM | 6.4 | 0.2% | May 2, 2026 | The Maxi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `/wp-json/maxi-blocks/v1.0/sty... |
| CVE-2026-7601 | MEDIUM | 5.3 | 0.4% | May 2, 2026 | A vulnerability has been found in Open5GS up to 2.7.6. Affected is an unknown function of the file src/amf/gmm-handler.c... |
| CVE-2026-7600 | MEDIUM | 6.3 | 1.1% | May 2, 2026 | A flaw has been found in ArtMin96 yii2-mcp-server 1.0.2. This impacts the function yii_command_help/yii_execute_command ... |
| CVE-2026-7599 | MEDIUM | 6.3 | 0.3% | May 1, 2026 | A vulnerability was detected in Dayoooun hwpx-mcp 0.2.0. This affects the function save_document/export_to_text/export_t... |
| CVE-2026-7597 | MEDIUM | 6.3 | 0.3% | May 1, 2026 | A vulnerability was found in mem0ai mem0 up to 1.0.11. This affects the function pickle.load/pickle.dump of the file mem... |
| CVE-2026-7596 | MEDIUM | 4.3 | 0.4% | May 1, 2026 | A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the functi... |
| CVE-2026-7595 | MEDIUM | 6.3 | 0.2% | May 1, 2026 | A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the functio... |
| CVE-2026-42788 | MEDIUM | 6.9 | 0.5% | May 1, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated memory exhau... |
| CVE-2026-39807 | MEDIUM | 6.3 | 0.5% | May 1, 2026 | Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-sta... |
| CVE-2026-39805 | MEDIUM | 6.3 | 0.5% | May 1, 2026 | Inconsistent Interpretation of HTTP Requests vulnerability in mtrudel bandit allows HTTP request smuggling via duplicate... |
| CVE-2026-7591 | MEDIUM | 6.3 | 0.2% | May 1, 2026 | A security flaw has been discovered in TimBroddin astro-mcp-server up to 1.1.1. The impacted element is an unknown funct... |
| CVE-2026-7589 | MEDIUM | 5.5 | 0.4% | May 1, 2026 | A vulnerability was determined in ghantakiran splunk-mcp-integration up to 0b86b09d5e5adf0433acd43c975951224613a1a6. Imp... |
| CVE-2026-7588 | MEDIUM | 5.5 | 0.4% | May 1, 2026 | A vulnerability was found in ggerve coding-standards-mcp. This issue affects the function get_style_guide/get_best_pract... |
| CVE-2026-35233 | MEDIUM | 4.4 | 0.1% | May 1, 2026 | An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link f... |
| CVE-2026-26461 | MEDIUM | 6.5 | 0.8% | May 1, 2026 | A Command Injection vulnerability in the web management interface in Aver PTC320UV2 0.1.0000.65 allows an unauthenticate... |
| CVE-2026-21996 | MEDIUM | 5.5 | 0.1% | May 1, 2026 | An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an intege... |
| CVE-2026-7587 | MEDIUM | 4.3 | 0.3% | May 1, 2026 | A vulnerability has been found in Open5GS up to 2.7.7. This vulnerability affects the function amf_nsmf_pdusession_handl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now