2026 CVE Vulnerabilities
65,056 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5502 | MEDIUM | 5.3 | 0.5% | Apr 17, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content m... |
| CVE-2026-5427 | MEDIUM | 5.3 | 0.5% | Apr 17, 2026 | The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due... |
| CVE-2026-5234 | MEDIUM | 5.3 | 0.7% | Apr 17, 2026 | The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin... |
| CVE-2026-4853 | MEDIUM | 4.9 | 0.7% | Apr 17, 2026 | The JetBackup – Backup, Restore & Migrate plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary Dire... |
| CVE-2026-3330 | MEDIUM | 4.9 | 0.4% | Apr 17, 2026 | The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate',... |
| CVE-2026-5052 | HIGH | 8.6 | 0.3% | Apr 17, 2026 | Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This ... |
| CVE-2026-4666 | MEDIUM | 6.5 | 0.3% | Apr 17, 2026 | The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($arg... |
| CVE-2026-4525 | HIGH | 8.8 | 0.4% | Apr 17, 2026 | If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used t... |
| CVE-2026-3605 | HIGH | 8.1 | 0.4% | Apr 17, 2026 | An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they w... |
| CVE-2026-5231 | HIGH | 7.2 | 0.5% | Apr 17, 2026 | The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in al... |
| CVE-2026-5162 | MEDIUM | 6.4 | 0.4% | Apr 17, 2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed ... |
| CVE-2026-4817 | MEDIUM | 6.5 | 0.5% | Apr 17, 2026 | The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based B... |
| CVE-2026-3488 | MEDIUM | 6.5 | 0.3% | Apr 17, 2026 | The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.1... |
| CVE-2026-40922 | MEDIUM | 5.4 | 0.3% | Apr 17, 2026 | SiYuan is an open-source personal knowledge management system. In versions 3.6.1 through 3.6.3, a prior fix for XSS in b... |
| CVE-2026-40265 | MEDIUM | 5.9 | 0.4% | Apr 17, 2026 | Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/n... |
| CVE-2026-40263 | LOW | 3.7 | 0.2% | Apr 17, 2026 | Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the login endpoint performs bcrypt pa... |
| CVE-2026-40262 | HIGH | 8.7 | 0.3% | Apr 17, 2026 | Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves upl... |
| CVE-2026-40260 | MEDIUM | 5.3 | 0.4% | Apr 17, 2026 | pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity de... |
| CVE-2026-22734 | HIGH | 8.6 | 0.4% | Apr 17, 2026 | Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UA... |
| CVE-2026-40322 | CRITICAL | 9 | 0.3% | Apr 16, 2026 | SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendere... |
| CVE-2026-40318 | HIGH | 8.5 | 0.3% | Apr 16, 2026 | SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttr... |
| CVE-2026-40259 | HIGH | 8.1 | 0.4% | Apr 16, 2026 | SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api/av/removeUnusedAttr... |
| CVE-2026-40255 | MEDIUM | 6.1 | 0.2% | Apr 16, 2026 | AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server version... |
| CVE-2026-40253 | MEDIUM | 6.1 | 0.2% | Apr 16, 2026 | openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER deco... |
| CVE-2026-41113 | HIGH | 8.1 | 0.9% | Apr 16, 2026 | sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remot... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now