2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31924 | MEDIUM | 5.3 | 0.2% | Apr 14, 2026 | Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plain... |
| CVE-2026-31923 | HIGH | 7.5 | 0.3% | Apr 14, 2026 | Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in o... |
| CVE-2026-31908 | CRITICAL | 9.1 | 0.5% | Apr 14, 2026 | Header injection vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in forward-au... |
| CVE-2026-27668 | HIGH | 8.8 | 0.3% | Apr 14, 2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). U... |
| CVE-2026-25654 | HIGH | 8.8 | 0.5% | Apr 14, 2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate u... |
| CVE-2026-24032 | HIGH | 7.3 | 0.3% | Apr 14, 2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains a... |
| CVE-2026-2582 | MEDIUM | 6.5 | 0.4% | Apr 14, 2026 | The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_hold... |
| CVE-2026-3017 | HIGH | 7.2 | 0.5% | Apr 14, 2026 | The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to P... |
| CVE-2026-4479 | MEDIUM | 4.4 | 0.2% | Apr 14, 2026 | The WholeSale Products Dynamic Pricing Management WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2026-4059 | MEDIUM | 6.4 | 0.3% | Apr 14, 2026 | The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentor_quickview_button shor... |
| CVE-2026-40315 | CRITICAL | 9.8 | 0.3% | Apr 14, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteC... |
| CVE-2026-40313 | CRITICAL | 9.1 | 0.3% | Apr 14, 2026 | PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to A... |
| CVE-2026-40289 | CRITICAL | 9.1 | 0.4% | Apr 14, 2026 | PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the brow... |
| CVE-2026-40288 | CRITICAL | 9.8 | 0.6% | Apr 14, 2026 | PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the work... |
| CVE-2026-40287 | HIGH | 8.4 | 0.2% | Apr 14, 2026 | PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through a... |
| CVE-2026-1607 | MEDIUM | 6.4 | 0.2% | Apr 14, 2026 | The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `s... |
| CVE-2026-6264 | CRITICAL | 9.8 | 0.7% | Apr 14, 2026 | A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the... |
| CVE-2026-6227 | HIGH | 7.2 | 1.3% | Apr 14, 2026 | The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/... |
| CVE-2026-4388 | HIGH | 7.2 | 0.2% | Apr 14, 2026 | The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box... |
| CVE-2026-34984 | MEDIUM | 6.5 | 0.3% | Apr 14, 2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete... |
| CVE-2026-4365 | CRITICAL | 9.1 | 0.9% | Apr 14, 2026 | The LearnPress plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the... |
| CVE-2026-4352 | HIGH | 7.5 | 0.4% | Apr 14, 2026 | The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endp... |
| CVE-2026-39426 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS... |
| CVE-2026-39425 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS... |
| CVE-2026-39419 | LOW | 3.1 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an authenticated user can bypass sandb... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now