2026 CVE Vulnerabilities

64,868 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7581MEDIUM4.3A security vulnerability has been detected in alexta69 MeTube up to 2026.04.09. This affects the function on_prepare of ...
CVE-2026-7580MEDIUM5.3A vulnerability was detected in Exiftool up to 13.53. Impacted is the function Process_mrld of the file lib/Image/ExifTo...
CVE-2026-7579HIGH7.3A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.16.0. This issue affects some unknown processi...
CVE-2026-3772HIGH8.8The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2...
CVE-2026-3140MEDIUM4.3The Ultimate Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2026-7578MEDIUM4.7A weakness has been identified in MacCMS Pro up to 2022.1.3. This vulnerability affects the function install of the file...
CVE-2026-42779CRITICAL9.8The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: ...
CVE-2026-42778CRITICAL9.8The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: ...
CVE-2026-42404HIGH7.2Apache Neethi does not impose any restrictions on URIs when manually fetching remote policy references through the Polic...
CVE-2026-7567CRITICAL9.8The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. T...
CVE-2026-43003HIGH7.5An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes execu...
CVE-2026-43001HIGH8An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-suppl...
CVE-2026-42403HIGH7.5Apache Neethi does not properly detect circular references in policy definitions. When a WS-Policy document contains cir...
CVE-2026-42402HIGH7.5Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specia...
CVE-2026-40201MEDIUM5.4@diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via the title in a .md file.
CVE-2026-7584HIGH8.4The LabOne Q serialization framework uses a class-loading mechanism (import_cls) to dynamically import and instantiate P...
CVE-2026-42996CRITICAL10JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @AP...
CVE-2026-7555HIGH7.3A vulnerability was identified in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /...
CVE-2026-7554HIGH8.1A vulnerability was determined in D-Link M60 up to 1.20B02. Affected by this issue is some unknown functionality of the ...
CVE-2026-6127MEDIUM6.4The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _elementor_data ...
CVE-2026-7553MEDIUM4.7A vulnerability was found in code-projects Gym Management System 1.0. Affected by this vulnerability is an unknown funct...
CVE-2026-7550HIGH7.3A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected is an unknown functio...
CVE-2026-7549HIGH7.3A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the...
CVE-2026-42994CRITICAL9.8Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code....
CVE-2026-7548HIGH8.8A vulnerability was detected in Totolink NR1800X 9.1.0u.6279_B20210910. This affects the function sub_41A68C of the file...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now