2026 CVE Vulnerabilities
50,985 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4031 | HIGH | 7.5 | 0.5% | May 14, 2026 | The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and ... |
| CVE-2026-4030 | HIGH | 8.1 | 0.5% | May 14, 2026 | The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in... |
| CVE-2026-4029 | HIGH | 7.5 | 0.4% | May 14, 2026 | The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up ... |
| CVE-2026-8468 | HIGH | 8.2 | 0.6% | May 14, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unb... |
| CVE-2026-6514 | HIGH | 7.5 | 0.3% | May 14, 2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2... |
| CVE-2026-6506 | HIGH | 8.8 | 0.3% | May 14, 2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.1.... |
| CVE-2026-5395 | HIGH | 8.2 | 0.2% | May 14, 2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
| CVE-2026-3892 | HIGH | 8.1 | 0.3% | May 14, 2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion i... |
| CVE-2026-3718 | HIGH | 7.2 | 0.3% | May 14, 2026 | The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'MWP-Key-Name' HTTP reques... |
| CVE-2026-5396 | HIGH | 8.2 | 0.2% | May 14, 2026 | The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions ... |
| CVE-2026-1659 | HIGH | 7.5 | 0.4% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and ... |
| CVE-2026-1322 | HIGH | 8.1 | 0.3% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2026-1184 | HIGH | 7.5 | 0.3% | May 14, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18... |
| CVE-2026-46446 | HIGH | 7.1 | 0.2% | May 14, 2026 | SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This i... |
| CVE-2026-46445 | HIGH | 7.1 | 0.2% | May 14, 2026 | SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection. |
| CVE-2026-46419 | HIGH | 7.5 | 0.3% | May 14, 2026 | Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value i... |
| CVE-2026-32991 | HIGH | 7.1 | 0.2% | May 13, 2026 | Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner ac... |
| CVE-2026-29206 | HIGH | 8.1 | 0.3% | May 13, 2026 | Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the roo... |
| CVE-2026-44478 | HIGH | 7.5 | 0.2% | May 13, 2026 | hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the una... |
| CVE-2026-44471 | HIGH | 7.8 | 0.2% | May 13, 2026 | gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, wh... |
| CVE-2026-44447 | HIGH | 7.5 | 0.3% | May 13, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to ... |
| CVE-2026-44446 | HIGH | 7.5 | 0.3% | May 13, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were ... |
| CVE-2026-44439 | HIGH | 7.5 | 0.3% | May 13, 2026 | PlaywrightCapture is a simple replacement for splash using playwright. Prior to 1.39.6, PlaywrightCapture did not suffic... |
| CVE-2026-44369 | HIGH | 8.5 | 0.3% | May 13, 2026 | CVAT is an open source interactive video and image annotation tool for computer vision. From 2.5.0 to 2.63.0, an attacke... |
| CVE-2026-42463 | HIGH | 8.1 | 0.2% | May 13, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now