2026 CVE Vulnerabilities
66,316 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5531 | MEDIUM | 5.5 | 0.2% | Apr 5, 2026 | A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function o... |
| CVE-2026-5530 | MEDIUM | 6.3 | 0.3% | Apr 5, 2026 | A flaw has been found in Ollama up to 0.18.1. This issue affects some unknown processing of the file server/download.go ... |
| CVE-2026-5529 | MEDIUM | 4.3 | 0.3% | Apr 5, 2026 | A vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the ... |
| CVE-2026-5528 | MEDIUM | 6.3 | 1.5% | Apr 5, 2026 | A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown par... |
| CVE-2026-5527 | MEDIUM | 5.5 | 0.4% | Apr 5, 2026 | A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown fu... |
| CVE-2026-5526 | CRITICAL | 9.8 | 0.4% | Apr 4, 2026 | A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerabil... |
| CVE-2026-3666 | HIGH | 8.8 | 0.4% | Apr 4, 2026 | The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4... |
| CVE-2026-3309 | MEDIUM | 6.5 | 0.4% | Apr 4, 2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres... |
| CVE-2026-2936 | HIGH | 7.2 | 0.3% | Apr 4, 2026 | The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page... |
| CVE-2026-1233 | HIGH | 7.5 | 0.3% | Apr 4, 2026 | The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure i... |
| CVE-2026-0626 | MEDIUM | 6.4 | 0.2% | Apr 4, 2026 | The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulner... |
| CVE-2026-5425 | HIGH | 7.2 | 0.2% | Apr 4, 2026 | The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' ... |
| CVE-2026-3445 | HIGH | 7.1 | 0.2% | Apr 4, 2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres... |
| CVE-2026-2826 | MEDIUM | 4.3 | 0.3% | Apr 4, 2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypas... |
| CVE-2026-2437 | MEDIUM | 6.4 | 0.2% | Apr 4, 2026 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2026-4896 | HIGH | 8.1 | 0.4% | Apr 4, 2026 | The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is... |
| CVE-2026-2600 | MEDIUM | 6.4 | 0.3% | Apr 4, 2026 | The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2026-0738 | MEDIUM | 6.4 | 0.3% | Apr 4, 2026 | The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2026-0737 | MEDIUM | 6.4 | 0.3% | Apr 4, 2026 | The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ... |
| CVE-2026-0664 | MEDIUM | 6.4 | 0.3% | Apr 4, 2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' p... |
| CVE-2026-0552 | MEDIUM | 6.4 | 0.2% | Apr 4, 2026 | The Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsc_displa... |
| CVE-2026-2949 | MEDIUM | 6.4 | 0.2% | Apr 4, 2026 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the I... |
| CVE-2026-2924 | MEDIUM | 6.4 | 0.2% | Apr 4, 2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Sit... |
| CVE-2026-3571 | MEDIUM | 6.5 | 0.3% | Apr 4, 2026 | The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized ... |
| CVE-2026-35616 | CRITICAL | 9.8 | 88.9% | Apr 4, 2026 | A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now