2026 CVE Vulnerabilities
50,042 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6080 | MEDIUM | 6.5 | 0.5% | Apr 17, 2026 | The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to ... |
| CVE-2026-5502 | MEDIUM | 5.3 | 0.5% | Apr 17, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content m... |
| CVE-2026-5427 | MEDIUM | 5.3 | 0.5% | Apr 17, 2026 | The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due... |
| CVE-2026-5234 | MEDIUM | 5.3 | 0.7% | Apr 17, 2026 | The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin... |
| CVE-2026-4853 | MEDIUM | 4.9 | 0.7% | Apr 17, 2026 | The JetBackup – Backup, Restore & Migrate plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary Dire... |
| CVE-2026-3330 | MEDIUM | 4.9 | 0.4% | Apr 17, 2026 | The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate',... |
| CVE-2026-4666 | MEDIUM | 6.5 | 0.3% | Apr 17, 2026 | The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($arg... |
| CVE-2026-5162 | MEDIUM | 6.4 | 0.4% | Apr 17, 2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed ... |
| CVE-2026-4817 | MEDIUM | 6.5 | 0.5% | Apr 17, 2026 | The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based B... |
| CVE-2026-3488 | MEDIUM | 6.5 | 0.3% | Apr 17, 2026 | The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.1... |
| CVE-2026-40922 | MEDIUM | 5.4 | 0.3% | Apr 17, 2026 | SiYuan is an open-source personal knowledge management system. In versions 3.6.1 through 3.6.3, a prior fix for XSS in b... |
| CVE-2026-40265 | MEDIUM | 5.9 | 0.4% | Apr 17, 2026 | Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/n... |
| CVE-2026-40260 | MEDIUM | 5.3 | 0.4% | Apr 17, 2026 | pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity de... |
| CVE-2026-40255 | MEDIUM | 6.1 | 0.2% | Apr 16, 2026 | AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server version... |
| CVE-2026-40253 | MEDIUM | 6.1 | 0.2% | Apr 16, 2026 | openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER deco... |
| CVE-2026-40249 | MEDIUM | 5.3 | 0.3% | Apr 16, 2026 | free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the PUT... |
| CVE-2026-35469 | MEDIUM | 6.5 | 0.7% | Apr 16, 2026 | spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame... |
| CVE-2026-34164 | MEDIUM | 4.9 | 0.4% | Apr 16, 2026 | Valtimo is an open-source business process automation platform. In versions 13.0.0 through 13.21.0, the InboxHandlingSer... |
| CVE-2026-33472 | MEDIUM | 4.8 | 0.1% | Apr 16, 2026 | Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw... |
| CVE-2026-40899 | MEDIUM | 6.5 | 0.4% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC paramete... |
| CVE-2026-24749 | MEDIUM | 5.3 | 0.4% | Apr 16, 2026 | The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-r... |
| CVE-2026-37100 | MEDIUM | 6.5 | 0.3% | Apr 16, 2026 | An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: ... |
| CVE-2026-37346 | MEDIUM | 4.7 | 0.2% | Apr 16, 2026 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_a... |
| CVE-2026-2840 | MEDIUM | 6.4 | 0.3% | Apr 16, 2026 | The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2026-6410 | MEDIUM | 5.3 | 0.5% | Apr 16, 2026 | @fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now