2026 CVE Vulnerabilities
51,426 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7647 | HIGH | 8.1 | 0.5% | May 2, 2026 | The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3... |
| CVE-2026-7049 | HIGH | 7.2 | 0.6% | May 2, 2026 | The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery... |
| CVE-2026-5113 | HIGH | 7.2 | 0.2% | May 2, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in v... |
| CVE-2026-5112 | HIGH | 7.2 | 0.2% | May 2, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to an... |
| CVE-2026-5111 | HIGH | 7.2 | 0.3% | May 2, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10... |
| CVE-2026-5110 | HIGH | 7.2 | 0.2% | May 2, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to an... |
| CVE-2026-5109 | HIGH | 7.2 | 0.2% | May 2, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10... |
| CVE-2026-7641 | HIGH | 8.8 | 0.7% | May 2, 2026 | The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up ... |
| CVE-2026-6963 | HIGH | 8.8 | 0.4% | May 2, 2026 | The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the w... |
| CVE-2026-43824 | HIGH | 7.7 | 0.2% | May 2, 2026 | In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data. |
| CVE-2026-7598 | HIGH | 7.3 | 0.5% | May 1, 2026 | A security vulnerability has been detected in libssh2 up to 1.11.1. The impacted element is the function userauth_passwo... |
| CVE-2026-7594 | HIGH | 7.3 | 0.4% | May 1, 2026 | A vulnerability was detected in Flux159 mcp-game-asset-gen 0.1.0. Affected is the function image_to_3d_async of the file... |
| CVE-2026-7593 | HIGH | 7.3 | 1.4% | May 1, 2026 | A security vulnerability has been detected in Sunwood-ai-labs command-executor-mcp-server up to 0.1.0. This impacts the ... |
| CVE-2026-42786 | HIGH | 8.7 | 0.5% | May 1, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denia... |
| CVE-2026-39804 | HIGH | 8.2 | 0.6% | May 1, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denia... |
| CVE-2026-7592 | HIGH | 7.3 | 0.3% | May 1, 2026 | A weakness has been identified in itsourcecode Courier Management System 1.0. This affects an unknown function of the fi... |
| CVE-2026-7590 | HIGH | 7.3 | 1.4% | May 1, 2026 | A vulnerability was identified in eyal-gor p_69_branch_monkey_mcp up to 69bc71874ce40050ef45fde5a435855f18af3373. The af... |
| CVE-2026-30363 | HIGH | 8.4 | 0.1% | May 1, 2026 | flipperzero-firmware commit ad2a80 was discovered to contain a stack overflow in the "Main" function. |
| CVE-2026-37457 | HIGH | 7.5 | 0.4% | May 1, 2026 | An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of F... |
| CVE-2026-42485 | HIGH | 7.5 | 0.3% | May 1, 2026 | AGL agl-service-can-low-level contains a stack buffer overflow in the uds-c library. The send_diagnostic_request functio... |
| CVE-2026-42469 | HIGH | 8.6 | 0.4% | May 1, 2026 | Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_canswitch.cpp the parser... |
| CVE-2026-42468 | HIGH | 8.8 | 0.4% | May 1, 2026 | Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_pcap.cpp , the parser's ... |
| CVE-2026-42467 | HIGH | 7.5 | 0.3% | May 1, 2026 | An issue was discovered in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939... |
| CVE-2026-37538 | HIGH | 7.5 | 0.3% | May 1, 2026 | Buffer overflow vulnerability in socketcand 0.4.2 in file socketcand.c in function main allows attackers to cause a deni... |
| CVE-2026-37537 | HIGH | 8.1 | 0.2% | May 1, 2026 | collin80/Open-SAE-J1939 thru commit 744024d4306bc387857dfce439558336806acb06 (2023-03-08) contains an integer underflow ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now