2026 CVE Vulnerabilities
64,952 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4106 | MEDIUM | 5.3 | 0.7% | Apr 23, 2026 | The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some P... |
| CVE-2026-41040 | HIGH | 8.7 | 0.4% | Apr 23, 2026 | GROWI provided by GROWI, Inc. is vulnerable to a regular expression denial of service (ReDoS) via a crafted input string... |
| CVE-2026-34488 | HIGH | 7.3 | 0.1% | Apr 23, 2026 | IP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Librar... |
| CVE-2026-41990 | MEDIUM | 4 | 0.2% | Apr 23, 2026 | Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attack... |
| CVE-2026-41989 | MEDIUM | 6.7 | 0.2% | Apr 23, 2026 | Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext ... |
| CVE-2026-41988 | LOW | 2.5 | 0.1% | Apr 23, 2026 | uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6.... |
| CVE-2026-41233 | MEDIUM | 5.4 | 0.3% | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` paramet... |
| CVE-2026-41232 | MEDIUM | 5 | 0.2% | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain owner... |
| CVE-2026-40529 | MEDIUM | 5.1 | 0.2% | Apr 23, 2026 | CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be ... |
| CVE-2026-41231 | HIGH | 7.5 | 0.4% | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export de... |
| CVE-2026-41230 | HIGH | 8.5 | 0.3% | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DN... |
| CVE-2026-41229 | CRITICAL | 9.1 | 0.5% | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes ... |
| CVE-2026-41228 | CRITICAL | 9.9 | 0.5% | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.updat... |
| CVE-2026-3361 | MEDIUM | 6.4 | 0.2% | Apr 23, 2026 | The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpsl_address' post meta ... |
| CVE-2026-3007 | MEDIUM | 5.4 | 0.2% | Apr 23, 2026 | Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitr... |
| CVE-2026-3844 | CRITICAL | 9.8 | 36.5% | Apr 23, 2026 | The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the... |
| CVE-2026-2951 | MEDIUM | 5.4 | 0.2% | Apr 23, 2026 | The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2026-41679 | CRITICAL | 10 | 2.0% | Apr 23, 2026 | Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 202... |
| CVE-2026-41243 | MEDIUM | 5.4 | 0.2% | Apr 23, 2026 | OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `saf... |
| CVE-2026-41211 | CRITICAL | 10 | 0.3% | Apr 23, 2026 | Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` ac... |
| CVE-2026-41208 | HIGH | 8.8 | 0.6% | Apr 23, 2026 | Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @papercl... |
| CVE-2026-41206 | HIGH | 7.8 | 0.2% | Apr 23, 2026 | PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. The... |
| CVE-2026-41200 | HIGH | 8.5 | 0.3% | Apr 23, 2026 | STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Infor... |
| CVE-2026-41197 | CRITICAL | 9.3 | 0.4% | Apr 23, 2026 | Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system,... |
| CVE-2026-41196 | CRITICAL | 10 | 0.4% | Apr 23, 2026 | Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to versio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now