2026 CVE Vulnerabilities
65,724 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23818 | CRITICAL | 9.6 | 0.3% | Apr 7, 2026 | A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Pre... |
| CVE-2026-22679 | CRITICAL | 9.8 | 21.5% | Apr 7, 2026 | Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability ... |
| CVE-2026-22666 | HIGH | 8.6 | 15.5% | Apr 7, 2026 | Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_s... |
| CVE-2026-31842 | HIGH | 8.7 | 0.9% | Apr 7, 2026 | Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of t... |
| CVE-2026-4420 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker ... |
| CVE-2026-34904 | HIGH | 7.5 | 0.1% | Apr 7, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request... |
| CVE-2026-34903 | MEDIUM | 5.4 | 0.3% | Apr 7, 2026 | Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2026-34899 | MEDIUM | 5.3 | 0.2% | Apr 7, 2026 | Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiti... |
| CVE-2026-34896 | HIGH | 7.5 | 0.1% | Apr 7, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows C... |
| CVE-2026-34197 | HIGH | 8.8 | 97.2% | Apr 7, 2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br... |
| CVE-2026-33227 | MEDIUM | 4.3 | 0.4% | Apr 7, 2026 | Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ... |
| CVE-2026-28810 | LOW | 3.7 | 0.3% | Apr 7, 2026 | Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows D... |
| CVE-2026-3177 | MEDIUM | 5.3 | 0.2% | Apr 7, 2026 | The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul... |
| CVE-2026-5465 | HIGH | 8.8 | 0.6% | Apr 7, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object R... |
| CVE-2026-4079 | MEDIUM | 6.5 | 0.2% | Apr 7, 2026 | The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queri... |
| CVE-2026-1900 | MEDIUM | 6.5 | 0.2% | Apr 7, 2026 | The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated ... |
| CVE-2026-1114 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to t... |
| CVE-2026-1839 | HIGH | 7.8 | 0.3% | Apr 7, 2026 | A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code ... |
| CVE-2026-0740 | CRITICAL | 9.8 | 54.3% | Apr 7, 2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val... |
| CVE-2026-20446 | MEDIUM | 4.3 | 0.2% | Apr 7, 2026 | In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of serv... |
| CVE-2026-20433 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of... |
| CVE-2026-20432 | HIGH | 8 | 0.3% | Apr 7, 2026 | In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of... |
| CVE-2026-20431 | MEDIUM | 6.5 | 0.3% | Apr 7, 2026 | In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE ha... |
| CVE-2026-5719 | MEDIUM | 6.3 | 0.2% | Apr 7, 2026 | A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /... |
| CVE-2026-5705 | MEDIUM | 4.3 | 0.4% | Apr 7, 2026 | A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown f... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now