2026 CVE Vulnerabilities
50,911 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40825 | HIGH | 7 | 0.2% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view d... |
| CVE-2026-40824 | HIGH | 7 | 0.2% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view u... |
| CVE-2026-40823 | HIGH | 7 | 0.2% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct... |
| CVE-2026-40819 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task du... |
| CVE-2026-40818 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24confi_getDevic... |
| CVE-2026-40817 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAlarmProfiles fu... |
| CVE-2026-40816 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the mb24alarm.php files... |
| CVE-2026-40815 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24api_getUserAcc... |
| CVE-2026-40814 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dataapi.php files _... |
| CVE-2026-40813 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues funct... |
| CVE-2026-40812 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues funct... |
| CVE-2026-40811 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractservice ... |
| CVE-2026-40810 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endpoint d... |
| CVE-2026-3375 | HIGH | 7.2 | 0.4% | May 27, 2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/noti... |
| CVE-2026-9200 | HIGH | 7.5 | 0.5% | May 27, 2026 | The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2... |
| CVE-2026-8994 | HIGH | 8.1 | 0.4% | May 27, 2026 | The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.... |
| CVE-2026-8787 | HIGH | 8.8 | 0.3% | May 27, 2026 | The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to,... |
| CVE-2026-6268 | HIGH | 7.1 | 0.2% | May 27, 2026 | The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_n... |
| CVE-2026-49000 | HIGH | 7 | 0.1% | May 27, 2026 | An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequa... |
| CVE-2026-48962 | HIGH | 7.3 | 0.3% | May 27, 2026 | IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled ou... |
| CVE-2026-48961 | HIGH | 7.3 | 0.3% | May 27, 2026 | IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine... |
| CVE-2026-48959 | HIGH | 7.5 | 0.4% | May 27, 2026 | IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastFo... |
| CVE-2026-2253 | HIGH | 7.7 | 0.2% | May 27, 2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, d... |
| CVE-2026-9632 | HIGH | 8.8 | 0.5% | May 27, 2026 | A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of th... |
| CVE-2026-9631 | HIGH | 8.8 | 0.4% | May 27, 2026 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the functi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now