2026 CVE Vulnerabilities
50,066 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33472 | MEDIUM | 4.8 | 0.1% | Apr 16, 2026 | Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw... |
| CVE-2026-40899 | MEDIUM | 6.5 | 0.4% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC paramete... |
| CVE-2026-24749 | MEDIUM | 5.3 | 0.4% | Apr 16, 2026 | The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-r... |
| CVE-2026-37100 | MEDIUM | 6.5 | 0.3% | Apr 16, 2026 | An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: ... |
| CVE-2026-37346 | MEDIUM | 4.7 | 0.2% | Apr 16, 2026 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_a... |
| CVE-2026-2840 | MEDIUM | 6.4 | 0.3% | Apr 16, 2026 | The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2026-6410 | MEDIUM | 5.3 | 0.5% | Apr 16, 2026 | @fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option.... |
| CVE-2026-4160 | MEDIUM | 5.3 | 0.3% | Apr 16, 2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
| CVE-2026-6414 | MEDIUM | 5.9 | 0.4% | Apr 16, 2026 | @fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, ... |
| CVE-2026-3369 | MEDIUM | 5.4 | 0.3% | Apr 16, 2026 | The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2026-0718 | MEDIUM | 5.3 | 0.3% | Apr 16, 2026 | The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauthor... |
| CVE-2026-41034 | MEDIUM | 5 | 0.3% | Apr 16, 2026 | ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.c... |
| CVE-2026-41030 | MEDIUM | 6.2 | 0.2% | Apr 16, 2026 | In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM p... |
| CVE-2026-3995 | MEDIUM | 4.4 | 0.3% | Apr 16, 2026 | The OPEN-BRAIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'API Key' settings field in all... |
| CVE-2026-3875 | MEDIUM | 6.4 | 0.2% | Apr 16, 2026 | The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'betterdocs_feedback_form' shor... |
| CVE-2026-3355 | MEDIUM | 6.1 | 0.3% | Apr 16, 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsea... |
| CVE-2026-1572 | MEDIUM | 6.4 | 0.3% | Apr 16, 2026 | The Livemesh Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cro... |
| CVE-2026-3773 | MEDIUM | 6.5 | 0.3% | Apr 16, 2026 | The Accessibility Suite by Ability, Inc plugin for WordPress is vulnerable to SQL Injection via the 'scan_id' parameter ... |
| CVE-2026-3595 | MEDIUM | 5.3 | 0.4% | Apr 16, 2026 | The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu... |
| CVE-2026-3581 | MEDIUM | 5.3 | 0.3% | Apr 16, 2026 | The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and inclu... |
| CVE-2026-3551 | MEDIUM | 4.4 | 0.4% | Apr 16, 2026 | The Custom New User Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's admi... |
| CVE-2026-40118 | MEDIUM | 6.3 | 0.2% | Apr 16, 2026 | UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability.... |
| CVE-2026-5070 | MEDIUM | 6.4 | 0.2% | Apr 16, 2026 | The Vantage theme for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery block text content in versions ... |
| CVE-2026-4032 | MEDIUM | 6.1 | 0.2% | Apr 16, 2026 | The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in 'cc' comm... |
| CVE-2026-3878 | MEDIUM | 6.4 | 0.2% | Apr 16, 2026 | The WP Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdocs_options[icon_size]' parame... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now