2026 CVE Vulnerabilities
65,056 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6414 | MEDIUM | 5.9 | 0.4% | Apr 16, 2026 | @fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, ... |
| CVE-2026-5968 | — | — | — | Apr 16, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-31843 | CRITICAL | 10 | 2.8% | Apr 16, 2026 | The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update e... |
| CVE-2026-3489 | HIGH | 7.5 | 0.4% | Apr 16, 2026 | The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection vi... |
| CVE-2026-3369 | MEDIUM | 5.4 | 0.3% | Apr 16, 2026 | The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2026-3155 | LOW | 3.1 | 0.3% | Apr 16, 2026 | The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and... |
| CVE-2026-23772 | HIGH | 7.3 | 0.1% | Apr 16, 2026 | Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management... |
| CVE-2026-0718 | MEDIUM | 5.3 | 0.3% | Apr 16, 2026 | The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthor... |
| CVE-2026-41035 | HIGH | 7.8 | 0.4% | Apr 16, 2026 | In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiv... |
| CVE-2026-41034 | MEDIUM | 5 | 0.3% | Apr 16, 2026 | ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.c... |
| CVE-2026-41030 | MEDIUM | 6.2 | 0.2% | Apr 16, 2026 | In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM p... |
| CVE-2026-3995 | MEDIUM | 4.4 | 0.3% | Apr 16, 2026 | The OPEN-BRAIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' settings field in all... |
| CVE-2026-3876 | HIGH | 7.2 | 0.3% | Apr 16, 2026 | The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-short... |
| CVE-2026-3875 | MEDIUM | 6.4 | 0.2% | Apr 16, 2026 | The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'betterdocs_feedback_form' shor... |
| CVE-2026-3861 | HIGH | 7.1 | 0.3% | Apr 16, 2026 | LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web ... |
| CVE-2026-3355 | MEDIUM | 6.1 | 0.3% | Apr 16, 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsea... |
| CVE-2026-1620 | HIGH | 8.8 | 0.8% | Apr 16, 2026 | The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ... |
| CVE-2026-1572 | MEDIUM | 6.4 | 0.3% | Apr 16, 2026 | The Livemesh Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cro... |
| CVE-2026-5050 | HIGH | 7.5 | 0.2% | Apr 16, 2026 | The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptog... |
| CVE-2026-3773 | MEDIUM | 6.5 | 0.3% | Apr 16, 2026 | The Accessibility Suite by Ability, Inc plugin for WordPress is vulnerable to SQL Injection via the 'scan_id' parameter ... |
| CVE-2026-3614 | HIGH | 8.8 | 0.4% | Apr 16, 2026 | The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and includi... |
| CVE-2026-3599 | HIGH | 7.5 | 0.5% | Apr 16, 2026 | The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within... |
| CVE-2026-3596 | CRITICAL | 9.8 | 0.8% | Apr 16, 2026 | The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu... |
| CVE-2026-3595 | MEDIUM | 5.3 | 0.4% | Apr 16, 2026 | The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu... |
| CVE-2026-3581 | MEDIUM | 5.3 | 0.3% | Apr 16, 2026 | The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and inclu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now