2026 CVE Vulnerabilities
49,206 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7268 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This impacts the function save_category o... |
| CVE-2026-7267 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects an unknown function of the file /view... |
| CVE-2026-7266 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function save_o... |
| CVE-2026-7265 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the f... |
| CVE-2026-7264 | MEDIUM | 6.3 | 0.3% | Apr 28, 2026 | A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function get_cart_items o... |
| CVE-2026-41607 | MEDIUM | 6.5 | 0.9% | Apr 28, 2026 | Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommen... |
| CVE-2026-41606 | MEDIUM | 5.3 | 1.1% | Apr 28, 2026 | Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are reco... |
| CVE-2026-40980 | MEDIUM | 6.5 | 0.2% | Apr 28, 2026 | In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when ha... |
| CVE-2026-40979 | MEDIUM | 6.1 | 0.1% | Apr 28, 2026 | In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected version... |
| CVE-2026-7238 | MEDIUM | 4.7 | 0.2% | Apr 28, 2026 | A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PH... |
| CVE-2026-7235 | MEDIUM | 5.5 | 0.5% | Apr 28, 2026 | A security vulnerability has been detected in ErlichLiu claude-agent-sdk-master up to b185aa7ff0d864581257008077b4010fca... |
| CVE-2026-4911 | MEDIUM | 5.3 | 0.3% | Apr 28, 2026 | The Booking Package plugin for WordPress is vulnerable to Price Manipulation in versions up to, and including, 1.7.06 Th... |
| CVE-2026-4805 | MEDIUM | 6.4 | 0.2% | Apr 28, 2026 | The Woostify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5.0 T... |
| CVE-2026-41525 | MEDIUM | 6.5 | 0.1% | Apr 28, 2026 | KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of th... |
| CVE-2026-40966 | MEDIUM | 5.9 | 0.2% | Apr 28, 2026 | In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histo... |
| CVE-2026-7233 | MEDIUM | 6.1 | 0.2% | Apr 28, 2026 | A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gid... |
| CVE-2026-7230 | MEDIUM | 4.3 | 0.3% | Apr 28, 2026 | A vulnerability was found in SourceCodester Safety Anger Pad 1.0. The affected element is an unknown function. The manip... |
| CVE-2026-7229 | MEDIUM | 6.3 | 0.2% | Apr 28, 2026 | A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file ... |
| CVE-2026-5306 | MEDIUM | 5.4 | 0.2% | Apr 28, 2026 | The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unau... |
| CVE-2026-6809 | MEDIUM | 6.4 | 0.2% | Apr 28, 2026 | The Social Post Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Threads embed handler in... |
| CVE-2026-6725 | MEDIUM | 6.4 | 0.2% | Apr 28, 2026 | The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' ... |
| CVE-2026-6551 | MEDIUM | 6.4 | 0.2% | Apr 28, 2026 | The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' a... |
| CVE-2026-7217 | MEDIUM | 5.5 | 0.4% | Apr 28, 2026 | A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read... |
| CVE-2026-0711 | MEDIUM | 6.8 | 0.8% | Apr 28, 2026 | A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions ... |
| CVE-2026-7200 | MEDIUM | 4.3 | 0.3% | Apr 28, 2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is some unknown ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now