2026 CVE Vulnerabilities
51,359 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4060 | HIGH | 7.5 | 0.3% | May 2, 2026 | The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions u... |
| CVE-2026-7611 | HIGH | 8.1 | 0.2% | May 2, 2026 | A vulnerability was found in TRENDnet TEW-821DAP up to 1.12B01. This impacts the function platform_do_upgrade_cameo_dev ... |
| CVE-2026-7610 | HIGH | 8.1 | 0.3% | May 2, 2026 | A vulnerability has been found in TRENDnet TEW-821DAP 1.12B01. This affects an unknown function of the file /www/cgi/ssi... |
| CVE-2026-7609 | HIGH | 8.8 | 4.1% | May 2, 2026 | A flaw has been found in TRENDnet TEW-821DAP up to 1.12B01. The impacted element is the function tools_diagnostic of the... |
| CVE-2026-7491 | HIGH | 8.6 | 0.3% | May 2, 2026 | School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote att... |
| CVE-2026-7490 | HIGH | 7.2 | 0.5% | May 2, 2026 | CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to up... |
| CVE-2026-7489 | HIGH | 8.8 | 0.3% | May 2, 2026 | CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary ... |
| CVE-2026-7608 | HIGH | 8 | 5.2% | May 2, 2026 | A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic... |
| CVE-2026-5324 | HIGH | 7.2 | 0.4% | May 2, 2026 | The Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versio... |
| CVE-2026-7649 | HIGH | 7.5 | 0.3% | May 2, 2026 | The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is... |
| CVE-2026-7607 | HIGH | 8.8 | 0.6% | May 2, 2026 | A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function auto_update_firmware... |
| CVE-2026-7606 | HIGH | 8.1 | 0.2% | May 2, 2026 | A weakness has been identified in TRENDnet TEW-821DAP 1.12B01. This issue affects the function find_hwid/new_gui_update_... |
| CVE-2026-6229 | HIGH | 7.2 | 0.4% | May 2, 2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and incl... |
| CVE-2026-2052 | HIGH | 8.8 | 0.8% | May 2, 2026 | The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vuln... |
| CVE-2026-7647 | HIGH | 8.1 | 0.5% | May 2, 2026 | The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3... |
| CVE-2026-7049 | HIGH | 7.2 | 0.6% | May 2, 2026 | The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery... |
| CVE-2026-5113 | HIGH | 7.2 | 0.2% | May 2, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in v... |
| CVE-2026-5112 | HIGH | 7.2 | 0.2% | May 2, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to an... |
| CVE-2026-5111 | HIGH | 7.2 | 0.3% | May 2, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10... |
| CVE-2026-5110 | HIGH | 7.2 | 0.2% | May 2, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to an... |
| CVE-2026-5109 | HIGH | 7.2 | 0.2% | May 2, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10... |
| CVE-2026-7641 | HIGH | 8.8 | 0.7% | May 2, 2026 | The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up ... |
| CVE-2026-6963 | HIGH | 8.8 | 0.4% | May 2, 2026 | The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the w... |
| CVE-2026-43824 | HIGH | 7.7 | 0.2% | May 2, 2026 | In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data. |
| CVE-2026-7598 | HIGH | 7.3 | 0.5% | May 1, 2026 | A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_passwo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now