2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1923 | MEDIUM | 6.4 | 0.2% | Apr 23, 2026 | The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’... |
| CVE-2026-6878 | MEDIUM | 5.6 | 0.3% | Apr 23, 2026 | A vulnerability was identified in ByteDance verl up to 0.7.0. Affected is the function math_equal of the file prime_math... |
| CVE-2026-6874 | MEDIUM | 4.3 | 0.3% | Apr 23, 2026 | A vulnerability was determined in ericc-ch copilot-api up to 0.7.0. This impacts an unknown function of the file /token ... |
| CVE-2026-5926 | MEDIUM | 6.5 | 0.2% | Apr 23, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
| CVE-2026-4919 | MEDIUM | 4.8 | 0.2% | Apr 23, 2026 | IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative use... |
| CVE-2026-4918 | MEDIUM | 4.8 | 0.1% | Apr 23, 2026 | IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrat... |
| CVE-2026-4917 | MEDIUM | 4.9 | 0.4% | Apr 23, 2026 | IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker ... |
| CVE-2026-3621 | MEDIUM | 5.9 | 0.3% | Apr 23, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnera... |
| CVE-2026-1726 | MEDIUM | 4.8 | 0.2% | Apr 23, 2026 | IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthori... |
| CVE-2026-1352 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could... |
| CVE-2026-1274 | MEDIUM | 4.9 | 0.3% | Apr 23, 2026 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access m... |
| CVE-2026-1272 | MEDIUM | 4.3 | 0.2% | Apr 23, 2026 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user a... |
| CVE-2026-41314 | MEDIUM | 6.5 | 0.2% | Apr 22, 2026 | pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior ... |
| CVE-2026-41313 | MEDIUM | 6.5 | 0.2% | Apr 22, 2026 | pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior ... |
| CVE-2026-41312 | MEDIUM | 6.5 | 0.2% | Apr 22, 2026 | pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior ... |
| CVE-2026-41177 | MEDIUM | 5.5 | 0.3% | Apr 22, 2026 | Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Sq... |
| CVE-2026-41168 | MEDIUM | 5.3 | 0.3% | Apr 22, 2026 | pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior ... |
| CVE-2026-3837 | MEDIUM | 5.4 | 0.2% | Apr 22, 2026 | An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution wh... |
| CVE-2026-34068 | MEDIUM | 6.8 | 0.2% | Apr 22, 2026 | nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, ... |
| CVE-2026-34067 | MEDIUM | 6.5 | 0.3% | Apr 22, 2026 | nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, ... |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.2% | Apr 22, 2026 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It ... |
| CVE-2026-3673 | MEDIUM | 5.4 | 0.2% | Apr 22, 2026 | An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim ope... |
| CVE-2026-34066 | MEDIUM | 5.3 | 0.2% | Apr 22, 2026 | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryStor... |
| CVE-2026-34062 | MEDIUM | 5.3 | 0.3% | Apr 22, 2026 | nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and... |
| CVE-2026-41469 | MEDIUM | 5.2 | 0.2% | Apr 22, 2026 | Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaSc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now