2026 CVE Vulnerabilities
64,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4089 | MEDIUM | 6.4 | 0.3% | Apr 22, 2026 | The Twittee Text Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribut... |
| CVE-2026-4088 | MEDIUM | 6.4 | 0.4% | Apr 22, 2026 | The Switch CTA Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wppw_cta_box' shortcode in... |
| CVE-2026-4085 | MEDIUM | 6.4 | 0.3% | Apr 22, 2026 | The Easy Social Photos Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wrapper_class'... |
| CVE-2026-4082 | MEDIUM | 6.4 | 0.3% | Apr 22, 2026 | The ER Swiffy Insert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the [swiffy] shortcode in all... |
| CVE-2026-4076 | MEDIUM | 6.4 | 0.4% | Apr 22, 2026 | The Slider Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'category' and '... |
| CVE-2026-4074 | MEDIUM | 6.4 | 0.4% | Apr 22, 2026 | The Quran Live Multilanguage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cheikh' and 'lan... |
| CVE-2026-3362 | MEDIUM | 4.4 | 0.4% | Apr 22, 2026 | The Short Comment Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Minimum Count' setti... |
| CVE-2026-31433 | HIGH | 8.8 | 0.6% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial OOB in get_file_all_info() for... |
| CVE-2026-31432 | HIGH | 8.8 | 0.5% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound req... |
| CVE-2026-31431 | HIGH | 7.8 | 99.9% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-pla... |
| CVE-2026-2719 | MEDIUM | 4.4 | 0.3% | Apr 22, 2026 | The Private WP suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Exceptions' setting in a... |
| CVE-2026-2717 | MEDIUM | 5.5 | 0.5% | Apr 22, 2026 | The HTTP Headers plugin for WordPress is vulnerable to CRLF Injection in all versions up to, and including, 1.19.2. This... |
| CVE-2026-2714 | MEDIUM | 4.4 | 0.3% | Apr 22, 2026 | The Institute Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Enquiry Form Title' ... |
| CVE-2026-1845 | MEDIUM | 5.5 | 0.2% | Apr 22, 2026 | The Real Estate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions... |
| CVE-2026-1379 | MEDIUM | 4.4 | 0.3% | Apr 22, 2026 | The HTTP Headers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up... |
| CVE-2026-6842 | LOW | 2.5 | 0.1% | Apr 22, 2026 | A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directo... |
| CVE-2026-6023 | CRITICAL | 9.8 | 0.5% | Apr 22, 2026 | In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecu... |
| CVE-2026-6022 | HIGH | 7.5 | 0.3% | Apr 22, 2026 | In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vuln... |
| CVE-2026-40542 | HIGH | 7.3 | 0.6% | Apr 22, 2026 | Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-... |
| CVE-2026-6840 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected vers... |
| CVE-2026-6839 | MEDIUM | 6.6 | 0.1% | Apr 22, 2026 | Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access duri... |
| CVE-2026-41667 | MEDIUM | 6.6 | 0.2% | Apr 22, 2026 | Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing... |
| CVE-2026-41666 | MEDIUM | 6.6 | 0.1% | Apr 22, 2026 | Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during lo... |
| CVE-2026-41665 | MEDIUM | 6.1 | 0.1% | Apr 22, 2026 | Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory ini... |
| CVE-2026-41664 | MEDIUM | 6.6 | 0.1% | Apr 22, 2026 | Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now