2026 CVE Vulnerabilities
65,056 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35153 | MEDIUM | 6.7 | 0.2% | Apr 17, 2026 | Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers... |
| CVE-2026-35074 | MEDIUM | 6.7 | 0.6% | Apr 17, 2026 | Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers... |
| CVE-2026-35073 | MEDIUM | 6.7 | 0.6% | Apr 17, 2026 | Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers... |
| CVE-2026-35072 | MEDIUM | 6.7 | 0.6% | Apr 17, 2026 | Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers... |
| CVE-2026-23779 | MEDIUM | 6.7 | 0.5% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,... |
| CVE-2026-23776 | HIGH | 8.8 | 0.2% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,... |
| CVE-2026-6494 | MEDIUM | 5.3 | 0.3% | Apr 17, 2026 | A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by ... |
| CVE-2026-6439 | MEDIUM | 4.4 | 0.2% | Apr 17, 2026 | The VideoZen plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.1. Th... |
| CVE-2026-23778 | HIGH | 7.2 | 1.1% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,... |
| CVE-2026-23775 | MEDIUM | 5.7 | 0.3% | Apr 17, 2026 | Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 throu... |
| CVE-2026-6451 | MEDIUM | 4.3 | 0.2% | Apr 17, 2026 | The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to an... |
| CVE-2026-40002 | HIGH | 8.8 | 0.1% | Apr 17, 2026 | Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operatio... |
| CVE-2026-33392 | HIGH | 7.2 | 0.4% | Apr 17, 2026 | In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass |
| CVE-2026-23853 | HIGH | 8.4 | 0.2% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,... |
| CVE-2026-6443 | CRITICAL | 9.8 | 0.5% | Apr 17, 2026 | All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to ... |
| CVE-2026-6441 | MEDIUM | 4.3 | 0.3% | Apr 17, 2026 | The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due... |
| CVE-2026-4659 | HIGH | 7.5 | 0.9% | Apr 17, 2026 | The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV... |
| CVE-2026-6482 | HIGH | 7.8 | 0.2% | Apr 17, 2026 | The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to ... |
| CVE-2026-6421 | HIGH | 7 | 0.1% | Apr 17, 2026 | A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library... |
| CVE-2026-5797 | MEDIUM | 5.3 | 0.5% | Apr 17, 2026 | The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and inc... |
| CVE-2026-35496 | MEDIUM | 5.1 | 0.3% | Apr 17, 2026 | A path traversal vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative privileg... |
| CVE-2026-34018 | CRITICAL | 9.8 | 0.2% | Apr 17, 2026 | An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQ... |
| CVE-2026-21719 | HIGH | 8.6 | 1.2% | Apr 17, 2026 | An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative p... |
| CVE-2026-6080 | MEDIUM | 6.5 | 0.5% | Apr 17, 2026 | The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to ... |
| CVE-2026-5807 | HIGH | 7.5 | 0.7% | Apr 17, 2026 | Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now