2026 CVE Vulnerabilities

64,997 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4089MEDIUM6.4The Twittee Text Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribut...
CVE-2026-4088MEDIUM6.4The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_cta_box' shortcode in...
CVE-2026-4085MEDIUM6.4The Easy Social Photos Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper_class'...
CVE-2026-4082MEDIUM6.4The ER Swiffy Insert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [swiffy] shortcode in all...
CVE-2026-4076MEDIUM6.4The Slider Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'category' and '...
CVE-2026-4074MEDIUM6.4The Quran Live Multilanguage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cheikh' and 'lan...
CVE-2026-3362MEDIUM4.4The Short Comment Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Minimum Count' setti...
CVE-2026-31433HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial OOB in get_file_all_info() for...
CVE-2026-31432HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound req...
CVE-2026-31431HIGH7.8In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-pla...
CVE-2026-2719MEDIUM4.4The Private WP suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Exceptions' setting in a...
CVE-2026-2717MEDIUM5.5The HTTP Headers plugin for WordPress is vulnerable to CRLF Injection in all versions up to, and including, 1.19.2. This...
CVE-2026-2714MEDIUM4.4The Institute Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Enquiry Form Title' ...
CVE-2026-1845MEDIUM5.5The Real Estate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions...
CVE-2026-1379MEDIUM4.4The HTTP Headers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up...
CVE-2026-6842LOW2.5A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directo...
CVE-2026-6023CRITICAL9.8In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecu...
CVE-2026-6022HIGH7.5In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vuln...
CVE-2026-40542HIGH7.3Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-...
CVE-2026-6840MEDIUM5.5Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected vers...
CVE-2026-6839MEDIUM6.6Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access duri...
CVE-2026-41667MEDIUM6.6Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing...
CVE-2026-41666MEDIUM6.6Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during lo...
CVE-2026-41665MEDIUM6.1Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory ini...
CVE-2026-41664MEDIUM6.6Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now