2026 CVE Vulnerabilities
50,944 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9018 | HIGH | 8.8 | 0.5% | May 22, 2026 | The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation ... |
| CVE-2026-44409 | HIGH | 7.5 | 0.2% | May 22, 2026 | There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control m... |
| CVE-2026-4834 | HIGH | 7.5 | 0.3% | May 22, 2026 | The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to,... |
| CVE-2026-46597 | HIGH | 7.5 | 0.4% | May 22, 2026 | An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafte... |
| CVE-2026-39829 | HIGH | 7.5 | 0.5% | May 22, 2026 | The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessive... |
| CVE-2026-34911 | HIGH | 7.7 | 0.7% | May 22, 2026 | A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in Un... |
| CVE-2026-8434 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file resc... |
| CVE-2026-8433 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file resc... |
| CVE-2026-8432 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star... |
| CVE-2026-8427 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file remo... |
| CVE-2026-8416 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addF... |
| CVE-2026-8415 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/as... |
| CVE-2026-8414 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/dupl... |
| CVE-2026-8413 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/... |
| CVE-2026-8412 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk... |
| CVE-2026-8411 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/... |
| CVE-2026-8410 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/... |
| CVE-2026-8409 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delet... |
| CVE-2026-8428 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but... |
| CVE-2026-8426 | HIGH | 8.8 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepa... |
| CVE-2026-8421 | HIGH | 8.8 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/singl... |
| CVE-2026-8417 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_up... |
| CVE-2026-8350 | HIGH | 8.8 | 0.3% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to pr... |
| CVE-2026-8135 | HIGH | 7.2 | 0.5% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the Ex... |
| CVE-2026-8134 | HIGH | 7.2 | 0.7% | May 21, 2026 | Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTempl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now