2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4076 | MEDIUM | 6.4 | 0.4% | Apr 22, 2026 | The Slider Bootstrap Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'category' and '... |
| CVE-2026-4074 | MEDIUM | 6.4 | 0.4% | Apr 22, 2026 | The Quran Live Multilanguage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cheikh' and 'lan... |
| CVE-2026-3362 | MEDIUM | 4.4 | 0.4% | Apr 22, 2026 | The Short Comment Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Minimum Count' setti... |
| CVE-2026-2719 | MEDIUM | 4.4 | 0.3% | Apr 22, 2026 | The Private WP suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Exceptions' setting in a... |
| CVE-2026-2717 | MEDIUM | 5.5 | 0.5% | Apr 22, 2026 | The HTTP Headers plugin for WordPress is vulnerable to CRLF Injection in all versions up to, and including, 1.19.2. This... |
| CVE-2026-2714 | MEDIUM | 4.4 | 0.3% | Apr 22, 2026 | The Institute Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Enquiry Form Title' ... |
| CVE-2026-1845 | MEDIUM | 5.5 | 0.2% | Apr 22, 2026 | The Real Estate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions... |
| CVE-2026-1379 | MEDIUM | 4.4 | 0.3% | Apr 22, 2026 | The HTTP Headers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up... |
| CVE-2026-6840 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | Missing bounds validation for operator could allow out of range operator-code lookup during model loading Affected vers... |
| CVE-2026-6839 | MEDIUM | 6.6 | 0.1% | Apr 22, 2026 | Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access duri... |
| CVE-2026-41667 | MEDIUM | 6.6 | 0.2% | Apr 22, 2026 | Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing... |
| CVE-2026-41666 | MEDIUM | 6.6 | 0.1% | Apr 22, 2026 | Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during lo... |
| CVE-2026-41665 | MEDIUM | 6.1 | 0.1% | Apr 22, 2026 | Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory ini... |
| CVE-2026-41664 | MEDIUM | 6.6 | 0.1% | Apr 22, 2026 | Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with... |
| CVE-2026-40450 | MEDIUM | 6.6 | 0.1% | Apr 22, 2026 | Integer overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incorrect copy length and... |
| CVE-2026-40449 | MEDIUM | 6.6 | 0.1% | Apr 22, 2026 | Integer overflow in buffer size calculation could result in out of bounds memory access when handling large tensors in S... |
| CVE-2026-40448 | MEDIUM | 5.3 | 0.1% | Apr 22, 2026 | Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large ... |
| CVE-2026-22748 | MEDIUM | 6.5 | 0.2% | Apr 22, 2026 | Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusRea... |
| CVE-2026-40451 | MEDIUM | 6.1 | 0.2% | Apr 22, 2026 | DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which all... |
| CVE-2026-6835 | MEDIUM | 6.1 | 0.2% | Apr 22, 2026 | The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to ... |
| CVE-2026-6416 | MEDIUM | 4.9 | 0.3% | Apr 22, 2026 | Tanium addressed an uncontrolled resource consumption vulnerability in Interact. |
| CVE-2026-6386 | MEDIUM | 6.2 | 0.2% | Apr 22, 2026 | In order to apply a particular protection key to an address range, the kernel must update the corresponding page table e... |
| CVE-2026-41457 | MEDIUM | 6.9 | 0.3% | Apr 22, 2026 | OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that a... |
| CVE-2026-41136 | MEDIUM | 5.3 | 0.3% | Apr 22, 2026 | free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generati... |
| CVE-2026-41131 | MEDIUM | 5 | 0.1% | Apr 22, 2026 | OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, mode... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now