2026 CVE Vulnerabilities
51,426 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7674 | HIGH | 8.8 | 0.5% | May 3, 2026 | A flaw has been found in Shenzhen Libituo Technology LBT-T300-HW1 up to 1.2.8. This issue affects the function start_sin... |
| CVE-2026-7670 | HIGH | 7.3 | 0.3% | May 2, 2026 | A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSumma... |
| CVE-2026-7668 | HIGH | 7.3 | 0.3% | May 2, 2026 | A vulnerability was identified in MikroTik RouterOS 6.49.8. This vulnerability affects the function ASN1_STRING_data in ... |
| CVE-2026-7644 | HIGH | 7.3 | 0.3% | May 2, 2026 | A vulnerability has been found in ChatGPTNextWeb NextChat up to 2.16.1. Affected is the function addMcpServer of the fil... |
| CVE-2026-7632 | HIGH | 7.3 | 0.3% | May 2, 2026 | A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function ... |
| CVE-2026-7630 | HIGH | 7.3 | 0.4% | May 2, 2026 | A vulnerability has been found in innocommerce InnoShop up to 0.7.8. The affected element is the function InstallService... |
| CVE-2026-2554 | HIGH | 8.1 | 0.3% | May 2, 2026 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is... |
| CVE-2026-6320 | HIGH | 7.5 | 0.4% | May 2, 2026 | The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and... |
| CVE-2026-4100 | HIGH | 7.1 | 0.2% | May 2, 2026 | The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification and disruption of Stripe webhoo... |
| CVE-2026-4062 | HIGH | 7.5 | 0.3% | May 2, 2026 | The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'object_ids' and 'exclude_object_i... |
| CVE-2026-4061 | HIGH | 7.5 | 0.3% | May 2, 2026 | The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'map_post_type' parameter in all v... |
| CVE-2026-4060 | HIGH | 7.5 | 0.3% | May 2, 2026 | The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions u... |
| CVE-2026-7611 | HIGH | 8.1 | 0.2% | May 2, 2026 | A vulnerability was found in TRENDnet TEW-821DAP up to 1.12B01. This impacts the function platform_do_upgrade_cameo_dev ... |
| CVE-2026-7610 | HIGH | 8.1 | 0.3% | May 2, 2026 | A vulnerability has been found in TRENDnet TEW-821DAP 1.12B01. This affects an unknown function of the file /www/cgi/ssi... |
| CVE-2026-7609 | HIGH | 8.8 | 4.1% | May 2, 2026 | A flaw has been found in TRENDnet TEW-821DAP up to 1.12B01. The impacted element is the function tools_diagnostic of the... |
| CVE-2026-7491 | HIGH | 8.6 | 0.3% | May 2, 2026 | School App developed by Zyosoft has an Insecure Direct Object Reference vulnerability, allowing authenticated remote att... |
| CVE-2026-7490 | HIGH | 7.2 | 0.5% | May 2, 2026 | CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to up... |
| CVE-2026-7489 | HIGH | 8.8 | 0.3% | May 2, 2026 | CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary ... |
| CVE-2026-7608 | HIGH | 8 | 5.2% | May 2, 2026 | A vulnerability was detected in TRENDnet TEW-821DAP up to 1.12B01. The affected element is the function tools_diagnostic... |
| CVE-2026-5324 | HIGH | 7.2 | 0.4% | May 2, 2026 | The Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versio... |
| CVE-2026-7649 | HIGH | 7.5 | 0.3% | May 2, 2026 | The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is... |
| CVE-2026-7607 | HIGH | 8.8 | 0.6% | May 2, 2026 | A security vulnerability has been detected in TRENDnet TEW-821DAP 1.12B01. Impacted is the function auto_update_firmware... |
| CVE-2026-7606 | HIGH | 8.1 | 0.2% | May 2, 2026 | A weakness has been identified in TRENDnet TEW-821DAP 1.12B01. This issue affects the function find_hwid/new_gui_update_... |
| CVE-2026-6229 | HIGH | 7.2 | 0.4% | May 2, 2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and incl... |
| CVE-2026-2052 | HIGH | 8.8 | 0.8% | May 2, 2026 | The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vuln... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now