2026 CVE Vulnerabilities
49,109 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7388 | MEDIUM | 4.7 | 0.2% | Apr 29, 2026 | A weakness has been identified in EyouCMS up to 1.7.9. Impacted is the function editFile of the file application/admin/l... |
| CVE-2026-40230 | MEDIUM | 5.4 | 0.2% | Apr 29, 2026 | Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated a... |
| CVE-2026-40229 | MEDIUM | 5.4 | 0.2% | Apr 29, 2026 | Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can per... |
| CVE-2026-38993 | MEDIUM | 6.5 | 0.8% | Apr 29, 2026 | Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows aut... |
| CVE-2026-2810 | MEDIUM | 6.8 | 0.1% | Apr 29, 2026 | Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The succe... |
| CVE-2026-25852 | MEDIUM | 6.7 | 0.1% | Apr 29, 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D... |
| CVE-2026-42525 | MEDIUM | 4.3 | 0.2% | Apr 29, 2026 | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL... |
| CVE-2026-42522 | MEDIUM | 4.3 | 0.2% | Apr 29, 2026 | A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers wi... |
| CVE-2026-42521 | MEDIUM | 6.5 | 0.2% | Apr 29, 2026 | Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructor... |
| CVE-2026-42519 | MEDIUM | 4.3 | 0.2% | Apr 29, 2026 | A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overa... |
| CVE-2026-42648 | MEDIUM | 4.3 | 0.2% | Apr 29, 2026 | Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrec... |
| CVE-2026-42645 | MEDIUM | 4.3 | 0.1% | Apr 29, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Or... |
| CVE-2026-42644 | MEDIUM | 5.3 | 0.2% | Apr 29, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper BetterDocs bette... |
| CVE-2026-42643 | MEDIUM | 5.9 | 0.1% | Apr 29, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Image Wi... |
| CVE-2026-42642 | MEDIUM | 5.3 | 0.2% | Apr 29, 2026 | Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2026-42641 | MEDIUM | 5.4 | 0.1% | Apr 29, 2026 | Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request F... |
| CVE-2026-2902 | MEDIUM | 6.1 | 0.2% | Apr 29, 2026 | The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2026-22745 | MEDIUM | 5.3 | 0.3% | Apr 29, 2026 | Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More ... |
| CVE-2026-22740 | MEDIUM | 6.5 | 0.3% | Apr 29, 2026 | A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some... |
| CVE-2026-4019 | MEDIUM | 5.3 | 0.3% | Apr 29, 2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to unauthorized data access in all versions ... |
| CVE-2026-42412 | MEDIUM | 6.5 | 0.2% | Apr 29, 2026 | Missing Authorization vulnerability in weDevs WP User Frontend allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2026-21023 | MEDIUM | 5.5 | 0.1% | Apr 29, 2026 | Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local att... |
| CVE-2026-23773 | MEDIUM | 4.3 | 0.2% | Apr 29, 2026 | Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability.... |
| CVE-2026-7340 | MEDIUM | 4.3 | 0.2% | Apr 28, 2026 | Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker to perform an ou... |
| CVE-2026-7318 | MEDIUM | 5.9 | 0.2% | Apr 28, 2026 | A vulnerability was detected in elie mcp-project 0.1.0. The affected element is the function search_papers of the file r... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now