2026 CVE Vulnerabilities
65,664 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4788 | MEDIUM | 5.5 | 0.1% | Apr 8, 2026 | IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that could be read by a loc... |
| CVE-2026-3357 | HIGH | 8.8 | 0.5% | Apr 8, 2026 | IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the sys... |
| CVE-2026-1346 | HIGH | 7.8 | 0.2% | Apr 8, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
| CVE-2026-1343 | HIGH | 7.2 | 0.2% | Apr 8, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
| CVE-2026-5747 | HIGH | 8.7 | 0.2% | Apr 8, 2026 | An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and a... |
| CVE-2026-4406 | MEDIUM | 4.7 | 0.4% | Apr 8, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in t... |
| CVE-2026-4401 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bu... |
| CVE-2026-4394 | MEDIUM | 6.1 | 0.3% | Apr 8, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Ty... |
| CVE-2026-2263 | MEDIUM | 5.3 | 0.4% | Apr 8, 2026 | The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modific... |
| CVE-2026-1342 | HIGH | 7.9 | 0.2% | Apr 8, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
| CVE-2026-4656 | — | — | — | Apr 7, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-39936 | MEDIUM | 6.9 | 0.3% | Apr 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun... |
| CVE-2026-39935 | MEDIUM | 6.9 | 0.3% | Apr 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun... |
| CVE-2026-4065 | MEDIUM | 5.4 | 0.4% | Apr 7, 2026 | The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing cap... |
| CVE-2026-39937 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki... |
| CVE-2026-39934 | MEDIUM | 6.9 | 0.3% | Apr 7, 2026 | Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExper... |
| CVE-2026-39933 | MEDIUM | 6.9 | 0.3% | Apr 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun... |
| CVE-2026-39847 | HIGH | 7.5 | 0.5% | Apr 7, 2026 | Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handle... |
| CVE-2026-39846 | CRITICAL | 9 | 0.5% | Apr 7, 2026 | SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger re... |
| CVE-2026-35568 | MEDIUM | 5.7 | 0.1% | Apr 7, 2026 | MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk conta... |
| CVE-2026-35406 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS que... |
| CVE-2026-34781 | LOW | 3.3 | 0.1% | Apr 7, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5,... |
| CVE-2026-34765 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5,... |
| CVE-2026-34582 | CRITICAL | 9.1 | 0.2% | Apr 7, 2026 | Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records... |
| CVE-2026-34580 | HIGH | 7.5 | 0.2% | Apr 7, 2026 | Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name;... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now