2026 CVE Vulnerabilities
50,911 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40848 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the tag view due to impr... |
| CVE-2026-40847 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system_tag view due ... |
| CVE-2026-40846 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the system view due to i... |
| CVE-2026-40845 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the devices_configuratio... |
| CVE-2026-40844 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dashboard view due t... |
| CVE-2026-40843 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the alarming view due to... |
| CVE-2026-40842 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getWidgetTags functi... |
| CVE-2026-40841 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectTags funct... |
| CVE-2026-40840 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the VerifyCreateLicences... |
| CVE-2026-40839 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getComponentScalings... |
| CVE-2026-40838 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDeviceScalings fu... |
| CVE-2026-40837 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectScalings f... |
| CVE-2026-40836 | HIGH | 7.1 | 0.2% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the inmessage model due ... |
| CVE-2026-40835 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the saveObjectFromData f... |
| CVE-2026-40834 | HIGH | 7.1 | 0.2% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash_layout.php file... |
| CVE-2026-40833 | HIGH | 7.1 | 0.2% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dash.php files saveD... |
| CVE-2026-40832 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getDevicegroups func... |
| CVE-2026-40831 | HIGH | 7.1 | 0.3% | May 27, 2026 | An low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the Easy View due to imp... |
| CVE-2026-40830 | HIGH | 7 | 0.3% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the admin.mbnetj.php fil... |
| CVE-2026-40829 | HIGH | 7 | 0.3% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the view.html.php files ... |
| CVE-2026-40828 | HIGH | 7 | 0.3% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DeleteSysLogEntry fu... |
| CVE-2026-40827 | HIGH | 7 | 0.3% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _RemoveRequest funct... |
| CVE-2026-8832 | HIGH | 8.8 | 1.2% | May 27, 2026 | The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerab... |
| CVE-2026-8143 | HIGH | 7.2 | 0.2% | May 27, 2026 | The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state_iso'... |
| CVE-2026-6169 | HIGH | 7.2 | 0.6% | May 27, 2026 | The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now