2026 CVE Vulnerabilities
46,946 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34033 | MEDIUM | 5.4 | 0.4% | Jun 9, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issu... |
| CVE-2026-34031 | MEDIUM | 6.5 | 0.4% | Jun 9, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: throu... |
| CVE-2026-33582 | MEDIUM | 6.5 | 0.5% | Jun 9, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: throu... |
| CVE-2026-28262 | MEDIUM | 6 | 0.1% | Jun 9, 2026 | Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following')... |
| CVE-2026-25699 | MEDIUM | 6.1 | 0.4% | Jun 9, 2026 | Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Ap... |
| CVE-2026-25688 | MEDIUM | 6.1 | 0.4% | Jun 9, 2026 | Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: throu... |
| CVE-2026-41985 | MEDIUM | 5.1 | 0.1% | Jun 9, 2026 | UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser... |
| CVE-2026-41984 | MEDIUM | 5.2 | 0.1% | Jun 9, 2026 | UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser... |
| CVE-2026-41983 | MEDIUM | 4.3 | 0.2% | Jun 9, 2026 | Null pointer dereference vulnerability in the browser module. Impact: Successful exploitation of this vulnerability may ... |
| CVE-2026-41982 | MEDIUM | 6.4 | 0.1% | Jun 9, 2026 | Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availab... |
| CVE-2026-41981 | MEDIUM | 5.3 | 0.1% | Jun 9, 2026 | Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect av... |
| CVE-2026-41977 | MEDIUM | 5 | 0.1% | Jun 9, 2026 | DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability. |
| CVE-2026-41976 | MEDIUM | 6.6 | 0.1% | Jun 9, 2026 | Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2026-41973 | MEDIUM | 5.9 | 0.1% | Jun 9, 2026 | Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability... |
| CVE-2026-41972 | MEDIUM | 5.4 | 0.2% | Jun 9, 2026 | Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availabili... |
| CVE-2026-4986 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before ... |
| CVE-2026-41539 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remot... |
| CVE-2026-8977 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_ac... |
| CVE-2026-8940 | MEDIUM | 4.3 | 0.1% | Jun 9, 2026 | The WP Meta Sort Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2026-8910 | MEDIUM | 6.1 | 0.1% | Jun 9, 2026 | The WP Emoticon Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2026-8909 | MEDIUM | 4.3 | 0.1% | Jun 9, 2026 | The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.3.... |
| CVE-2026-8907 | MEDIUM | 6.1 | 0.1% | Jun 9, 2026 | The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1... |
| CVE-2026-8904 | MEDIUM | 4.3 | 0.1% | Jun 9, 2026 | The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin for WordPress is vu... |
| CVE-2026-8902 | MEDIUM | 4.3 | 0.1% | Jun 9, 2026 | The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2026-8895 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcod... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now