2026 CVE Vulnerabilities
50,000 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6048 | MEDIUM | 6.4 | 0.2% | Apr 18, 2026 | The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget... |
| CVE-2026-4801 | MEDIUM | 6.4 | 0.4% | Apr 18, 2026 | The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via exter... |
| CVE-2026-40490 | MEDIUM | 6.8 | 0.3% | Apr 18, 2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT... |
| CVE-2026-1838 | MEDIUM | 6.1 | 0.3% | Apr 18, 2026 | The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all ... |
| CVE-2026-1559 | MEDIUM | 6.4 | 0.2% | Apr 18, 2026 | The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in al... |
| CVE-2026-40593 | MEDIUM | 4.8 | 0.2% | Apr 18, 2026 | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) rende... |
| CVE-2026-40485 | MEDIUM | 5.3 | 0.3% | Apr 18, 2026 | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/pu... |
| CVE-2026-40483 | MEDIUM | 5.4 | 0.2% | Apr 18, 2026 | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation com... |
| CVE-2026-40347 | MEDIUM | 5.3 | 0.4% | Apr 18, 2026 | Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerabi... |
| CVE-2026-40346 | MEDIUM | 6.5 | 0.4% | Apr 18, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-40340 | MEDIUM | 6.1 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read vulner... |
| CVE-2026-40339 | MEDIUM | 5.2 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt... |
| CVE-2026-40338 | MEDIUM | 5.2 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the... |
| CVE-2026-40337 | MEDIUM | 5.1 | 0.2% | Apr 18, 2026 | The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given ... |
| CVE-2026-40335 | MEDIUM | 5.2 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt... |
| CVE-2026-40333 | MEDIUM | 6.1 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2... |
| CVE-2026-40486 | MEDIUM | 4.3 | 0.3% | Apr 17, 2026 | Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATC... |
| CVE-2026-40479 | MEDIUM | 5.4 | 0.2% | Apr 17, 2026 | Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in Ki... |
| CVE-2026-2434 | MEDIUM | 6.4 | 0.2% | Apr 17, 2026 | The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attribute... |
| CVE-2026-40353 | MEDIUM | 5.4 | 0.2% | Apr 17, 2026 | wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in Abs... |
| CVE-2026-40306 | MEDIUM | 6.5 | 0.2% | Apr 17, 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new in... |
| CVE-2026-40305 | MEDIUM | 4.3 | 0.2% | Apr 17, 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting i... |
| CVE-2026-40304 | MEDIUM | 5.3 | 0.3% | Apr 17, 2026 | zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (c... |
| CVE-2026-40302 | MEDIUM | 6.1 | 0.2% | Apr 17, 2026 | zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template en... |
| CVE-2026-40301 | MEDIUM | 4.7 | 0.3% | Apr 17, 2026 | DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now