2026 CVE Vulnerabilities
51,340 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7717 | HIGH | 8.8 | 0.5% | May 4, 2026 | A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. This issue affects the function UploadCustomModul... |
| CVE-2026-42365 | HIGH | 7.5 | 0.3% | May 4, 2026 | A guessable session cookie vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A ... |
| CVE-2026-42364 | HIGH | 8.8 | 1.6% | May 4, 2026 | An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A s... |
| CVE-2026-7711 | HIGH | 7.3 | 0.3% | May 4, 2026 | A weakness has been identified in MindsDB up to 26.01. This impacts the function exec of the file mindsdb/integrations/h... |
| CVE-2026-7710 | HIGH | 7.3 | 0.4% | May 4, 2026 | A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the... |
| CVE-2026-7703 | HIGH | 7.3 | 0.3% | May 3, 2026 | A flaw has been found in AV Stumpfl Pixera Two Media Server up to 25.2 R2. Impacted is an unknown function of the compon... |
| CVE-2026-7698 | HIGH | 7.3 | 1.7% | May 3, 2026 | A vulnerability was identified in Tiandy Easy7 Integrated Management Platform 7.17.0. Affected by this vulnerability is ... |
| CVE-2026-7695 | HIGH | 7.3 | 0.3% | May 3, 2026 | A vulnerability has been found in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0.... |
| CVE-2026-7694 | HIGH | 7.3 | 0.3% | May 3, 2026 | A flaw has been found in Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System 1.3.0. The impa... |
| CVE-2026-7685 | HIGH | 8.8 | 0.5% | May 3, 2026 | A vulnerability was detected in Edimax BR-6208AC up to 1.02. Affected is an unknown function of the file /goform/setWAN.... |
| CVE-2026-7684 | HIGH | 8.8 | 0.5% | May 3, 2026 | A security vulnerability has been detected in Edimax BR-6428nC up to 1.16. This impacts an unknown function of the file ... |
| CVE-2026-5063 | HIGH | 7.2 | 0.2% | May 3, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2026-7679 | HIGH | 7.3 | 0.4% | May 3, 2026 | A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This impacts the function getAccessToken of the... |
| CVE-2026-7675 | HIGH | 8.8 | 0.7% | May 3, 2026 | A vulnerability has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. Impacted is the function start_l... |
| CVE-2026-7674 | HIGH | 8.8 | 0.5% | May 3, 2026 | A flaw has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. This issue affects the function start_sin... |
| CVE-2026-7670 | HIGH | 7.3 | 0.3% | May 2, 2026 | A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSumma... |
| CVE-2026-7668 | HIGH | 7.3 | 0.3% | May 2, 2026 | A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in ... |
| CVE-2026-7644 | HIGH | 7.3 | 0.3% | May 2, 2026 | A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the fil... |
| CVE-2026-7632 | HIGH | 7.3 | 0.3% | May 2, 2026 | A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function ... |
| CVE-2026-7630 | HIGH | 7.3 | 0.4% | May 2, 2026 | A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallService... |
| CVE-2026-2554 | HIGH | 8.1 | 0.3% | May 2, 2026 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is... |
| CVE-2026-6320 | HIGH | 7.5 | 0.4% | May 2, 2026 | The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and... |
| CVE-2026-4100 | HIGH | 7.1 | 0.2% | May 2, 2026 | The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhoo... |
| CVE-2026-4062 | HIGH | 7.5 | 0.3% | May 2, 2026 | The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_i... |
| CVE-2026-4061 | HIGH | 7.5 | 0.3% | May 2, 2026 | The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all v... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now