2026 CVE Vulnerabilities
65,654 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2988 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podca... |
| CVE-2026-5726 | HIGH | 8.4 | 0.3% | Apr 8, 2026 | ASDA-Soft Stack-based Buffer Overflow Vulnerability |
| CVE-2026-1163 | MEDIUM | 4.1 | 0.2% | Apr 8, 2026 | An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails ... |
| CVE-2026-3499 | HIGH | 8.8 | 0.2% | Apr 8, 2026 | The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to C... |
| CVE-2026-3296 | CRITICAL | 9.8 | 3.5% | Apr 8, 2026 | The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3... |
| CVE-2026-33810 | HIGH | 8.2 | 0.3% | Apr 8, 2026 | When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to w... |
| CVE-2026-32289 | MEDIUM | 6.1 | 0.3% | Apr 8, 2026 | Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escapi... |
| CVE-2026-32288 | MEDIUM | 5.5 | 0.3% | Apr 8, 2026 | tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large numb... |
| CVE-2026-32283 | HIGH | 7.5 | 0.6% | Apr 8, 2026 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c... |
| CVE-2026-32282 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can ope... |
| CVE-2026-32281 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve... |
| CVE-2026-32280 | HIGH | 7.5 | 0.6% | Apr 8, 2026 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert... |
| CVE-2026-27144 | HIGH | 7.1 | 0.3% | Apr 8, 2026 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented... |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.5% | Apr 8, 2026 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp... |
| CVE-2026-27140 | HIGH | 8.8 | 0.7% | Apr 8, 2026 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at ... |
| CVE-2026-4788 | MEDIUM | 5.5 | 0.1% | Apr 8, 2026 | IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that could be read by a loc... |
| CVE-2026-3357 | HIGH | 8.8 | 0.5% | Apr 8, 2026 | IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the sys... |
| CVE-2026-1346 | HIGH | 7.8 | 0.2% | Apr 8, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
| CVE-2026-1343 | HIGH | 7.2 | 0.2% | Apr 8, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
| CVE-2026-5747 | HIGH | 8.7 | 0.2% | Apr 8, 2026 | An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and a... |
| CVE-2026-4406 | MEDIUM | 4.7 | 0.4% | Apr 8, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in t... |
| CVE-2026-4401 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bu... |
| CVE-2026-4394 | MEDIUM | 6.1 | 0.3% | Apr 8, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Ty... |
| CVE-2026-2263 | MEDIUM | 5.3 | 0.4% | Apr 8, 2026 | The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modific... |
| CVE-2026-1342 | HIGH | 7.9 | 0.2% | Apr 8, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now