2026 CVE Vulnerabilities
64,952 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-38743 | MEDIUM | 4.3 | 0.4% | Apr 24, 2026 | The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and Task... |
| CVE-2026-21515 | CRITICAL | 9.9 | 0.7% | Apr 24, 2026 | Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate... |
| CVE-2026-6043 | HIGH | 8.8 | 0.5% | Apr 24, 2026 | P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted network... |
| CVE-2026-4313 | LOW | 2.4 | 0.6% | Apr 24, 2026 | AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacker can replace the va... |
| CVE-2026-23902 | HIGH | 8.1 | 0.4% | Apr 24, 2026 | Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permission... |
| CVE-2026-41044 | HIGH | 8.8 | 1.0% | Apr 24, 2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, A... |
| CVE-2026-41043 | MEDIUM | 6.5 | 0.6% | Apr 24, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache A... |
| CVE-2026-40466 | HIGH | 8.8 | 4.8% | Apr 24, 2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br... |
| CVE-2026-6272 | HIGH | 8.5 | 0.3% | Apr 24, 2026 | A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v... |
| CVE-2026-21728 | HIGH | 7.5 | 0.6% | Apr 24, 2026 | Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, dep... |
| CVE-2026-4078 | MEDIUM | 6.4 | 0.3% | Apr 24, 2026 | The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes (iteras-ordering, i... |
| CVE-2026-3569 | MEDIUM | 5.3 | 0.4% | Apr 24, 2026 | The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1... |
| CVE-2026-3565 | MEDIUM | 4.3 | 0.2% | Apr 24, 2026 | The Taqnix plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3.... |
| CVE-2026-1952 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability. |
| CVE-2026-1951 | CRITICAL | 9.8 | 0.6% | Apr 24, 2026 | Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability. |
| CVE-2026-1950 | CRITICAL | 9.8 | 0.3% | Apr 24, 2026 | Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability. |
| CVE-2026-6810 | MEDIUM | 5.3 | 0.3% | Apr 24, 2026 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions... |
| CVE-2026-5428 | MEDIUM | 6.4 | 0.3% | Apr 24, 2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the I... |
| CVE-2026-5364 | HIGH | 8.1 | 1.1% | Apr 24, 2026 | The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions... |
| CVE-2026-5347 | MEDIUM | 5.3 | 0.3% | Apr 24, 2026 | The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. ... |
| CVE-2026-1949 | CRITICAL | 9.8 | 0.6% | Apr 24, 2026 | Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the... |
| CVE-2026-6947 | HIGH | 8.7 | 0.5% | Apr 24, 2026 | DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticat... |
| CVE-2026-6393 | MEDIUM | 4.3 | 0.3% | Apr 24, 2026 | The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This ... |
| CVE-2026-5488 | MEDIUM | 5.3 | 0.3% | Apr 24, 2026 | The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization ... |
| CVE-2026-41485 | HIGH | 7.7 | 0.4% | Apr 24, 2026 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now