2026 CVE Vulnerabilities
50,941 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9284 | HIGH | 8.2 | 0.4% | May 23, 2026 | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information di... |
| CVE-2026-6898 | HIGH | 8.8 | 0.2% | May 23, 2026 | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2026-6897 | HIGH | 8.8 | 0.2% | May 23, 2026 | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2026-6895 | HIGH | 8.8 | 0.2% | May 23, 2026 | The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclos... |
| CVE-2026-6419 | HIGH | 8.8 | 0.3% | May 23, 2026 | The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up ... |
| CVE-2026-45659 | HIGH | 8.8 | 3.2% | May 22, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne... |
| CVE-2026-42827 | HIGH | 7.5 | 0.5% | May 22, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz... |
| CVE-2026-41104 | HIGH | 7.5 | 0.9% | May 22, 2026 | Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose inform... |
| CVE-2026-40411 | HIGH | 8.8 | 0.5% | May 22, 2026 | Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network. |
| CVE-2026-35430 | HIGH | 8.8 | 0.4% | May 22, 2026 | Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized atta... |
| CVE-2026-26147 | HIGH | 7.7 | 0.6% | May 22, 2026 | Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network. |
| CVE-2026-23663 | HIGH | 7.5 | 0.6% | May 22, 2026 | Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-41147 | HIGH | 8.7 | 0.3% | May 22, 2026 | NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS)... |
| CVE-2026-41076 | HIGH | 8.1 | 0.4% | May 22, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 t... |
| CVE-2026-41075 | HIGH | 8.8 | 0.3% | May 22, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through ... |
| CVE-2026-41074 | HIGH | 7.1 | 0.1% | May 22, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Si... |
| CVE-2026-41071 | HIGH | 8.1 | 0.3% | May 22, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file w... |
| CVE-2026-3294 | HIGH | 8.8 | 0.4% | May 22, 2026 | An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjac... |
| CVE-2026-5843 | HIGH | 8.6 | 0.2% | May 22, 2026 | The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and exe... |
| CVE-2026-5817 | HIGH | 8.6 | 0.2% | May 22, 2026 | The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loadin... |
| CVE-2026-40607 | HIGH | 7.5 | 0.4% | May 22, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerabi... |
| CVE-2026-40597 | HIGH | 7.6 | 0.5% | May 22, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS ... |
| CVE-2026-40596 | HIGH | 7.2 | 0.4% | May 22, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated us... |
| CVE-2026-9291 | HIGH | 7.5 | 0.4% | May 22, 2026 | Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remot... |
| CVE-2026-6406 | HIGH | 8.8 | 0.2% | May 22, 2026 | The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When EC... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now