2026 CVE Vulnerabilities
65,007 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6758 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150... |
| CVE-2026-6757 | MEDIUM | 6.3 | 0.3% | Apr 21, 2026 | Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.1... |
| CVE-2026-6756 | HIGH | 7.5 | 0.2% | Apr 21, 2026 | Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150. |
| CVE-2026-6755 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
| CVE-2026-6754 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Fire... |
| CVE-2026-6753 | HIGH | 7.3 | 0.3% | Apr 21, 2026 | Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, ... |
| CVE-2026-6752 | HIGH | 7.3 | 0.3% | Apr 21, 2026 | Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, ... |
| CVE-2026-6751 | HIGH | 7.3 | 0.3% | Apr 21, 2026 | Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR ... |
| CVE-2026-6750 | HIGH | 8.8 | 0.5% | Apr 21, 2026 | Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.... |
| CVE-2026-6749 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in ... |
| CVE-2026-6748 | CRITICAL | 9.8 | 0.4% | Apr 21, 2026 | Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR ... |
| CVE-2026-6747 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150... |
| CVE-2026-6746 | HIGH | 7.5 | 0.6% | Apr 21, 2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firef... |
| CVE-2026-40520 | HIGH | 8.8 | 1.4% | Apr 21, 2026 | FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() fun... |
| CVE-2026-32147 | MEDIUM | 4.3 | 0.4% | Apr 21, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP ssh (ssh_sftp... |
| CVE-2026-41039 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | This vulnerability exists in Quantum Networks router due to improper access control and insecure default configuration i... |
| CVE-2026-41038 | HIGH | 8.8 | 0.2% | Apr 21, 2026 | This vulnerability exists in Quantum Networks router due to lack of enforcement of strong password policies in the web-b... |
| CVE-2026-6553 | HIGH | 7.5 | 0.2% | Apr 21, 2026 | Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and u... |
| CVE-2026-41037 | HIGH | 8.8 | 0.2% | Apr 21, 2026 | This vulnerability exists in Quantum Networks router due to missing rate limiting and CAPTCHA protection for failed logi... |
| CVE-2026-41036 | HIGH | 8.8 | 0.4% | Apr 21, 2026 | This vulnerability exists in Quantum Networks router due to inadequate sanitization of user-supplied input in the manage... |
| CVE-2026-3317 | MEDIUM | 5.1 | 0.3% | Apr 21, 2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present i... |
| CVE-2026-39467 | HIGH | 7.2 | 0.4% | Apr 21, 2026 | Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.Th... |
| CVE-2026-6712 | MEDIUM | 4.4 | 0.2% | Apr 21, 2026 | The Website LLMs.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all version... |
| CVE-2026-6711 | MEDIUM | 6.1 | 0.2% | Apr 21, 2026 | The Website LLMs.txt plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all... |
| CVE-2026-6703 | MEDIUM | 4.3 | 0.2% | Apr 21, 2026 | The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access in ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now