2026 CVE Vulnerabilities
50,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45837 | HIGH | 7.8 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free in arena_vm_close on fork ... |
| CVE-2026-42762 | HIGH | 7.1 | 0.1% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBookin... |
| CVE-2026-42760 | HIGH | 7.5 | 0.3% | May 27, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule ... |
| CVE-2026-42759 | HIGH | 7.1 | 0.1% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Affiliate Sup... |
| CVE-2026-42754 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phbernard Favicon ... |
| CVE-2026-42753 | HIGH | 7.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in WC Lovers WCFM Membership wc-multivendor-membership allows Exploiting Incorrectly... |
| CVE-2026-42749 | HIGH | 7.1 | 0.2% | May 27, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeisle Disable Comments for Any Post Types ... |
| CVE-2026-42746 | HIGH | 7.3 | 0.2% | May 27, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in ZAYTECH Smart Online Order for Clover clover-online-o... |
| CVE-2026-42745 | HIGH | 7.3 | 0.2% | May 27, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ZAYTECH Smart Online Order for Clover clover-o... |
| CVE-2026-42739 | HIGH | 7.1 | 0.1% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IniLerm Advanced I... |
| CVE-2026-42738 | HIGH | 7.1 | 0.1% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZAYTECH Smart Onli... |
| CVE-2026-42737 | HIGH | 8.6 | 0.3% | May 27, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hote... |
| CVE-2026-42736 | HIGH | 7.5 | 0.2% | May 27, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-better-messages allows ... |
| CVE-2026-42735 | HIGH | 8.2 | 0.3% | May 27, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-managem... |
| CVE-2026-42734 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Ma... |
| CVE-2026-42733 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 WPCS cu... |
| CVE-2026-42730 | HIGH | 8.5 | 0.3% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStu... |
| CVE-2026-42729 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive Prop... |
| CVE-2026-42728 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Cont... |
| CVE-2026-40852 | HIGH | 7.2 | 0.4% | May 27, 2026 | A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. T... |
| CVE-2026-40851 | HIGH | 8.4 | 0.1% | May 27, 2026 | A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to... |
| CVE-2026-40850 | HIGH | 8.7 | 0.4% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountData func... |
| CVE-2026-40849 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the user_alarmprofile vi... |
| CVE-2026-40848 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the tag view due to impr... |
| CVE-2026-40847 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system_tag view due ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now