2026 CVE Vulnerabilities
50,391 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2400 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application us... |
| CVE-2026-2399 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could ca... |
| CVE-2026-25691 | MEDIUM | 6.7 | 0.5% | Apr 14, 2026 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox ... |
| CVE-2026-22576 | MEDIUM | 6.5 | 0.3% | Apr 14, 2026 | A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS... |
| CVE-2026-22574 | MEDIUM | 6.5 | 0.3% | Apr 14, 2026 | A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS... |
| CVE-2026-22573 | MEDIUM | 6.5 | 0.4% | Apr 14, 2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR Pa... |
| CVE-2026-22154 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS... |
| CVE-2026-21742 | MEDIUM | 6.5 | 0.1% | Apr 14, 2026 | A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOA... |
| CVE-2026-21741 | MEDIUM | 4.8 | 0.2% | Apr 14, 2026 | An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.... |
| CVE-2026-4914 | MEDIUM | 5.4 | 0.3% | Apr 14, 2026 | Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information f... |
| CVE-2026-4913 | MEDIUM | 5.7 | 0.6% | Apr 14, 2026 | Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker t... |
| CVE-2026-37980 | MEDIUM | 4.8 | 0.2% | Apr 14, 2026 | A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-real... |
| CVE-2026-30480 | MEDIUM | 6.5 | 0.3% | Apr 14, 2026 | A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows ... |
| CVE-2026-24069 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to conti... |
| CVE-2026-4109 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to u... |
| CVE-2026-33929 | MEDIUM | 4.3 | 0.7% | Apr 14, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. ... |
| CVE-2026-31924 | MEDIUM | 5.3 | 0.2% | Apr 14, 2026 | Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. tencent-cloud-cls log export uses plain... |
| CVE-2026-2582 | MEDIUM | 6.5 | 0.4% | Apr 14, 2026 | The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_hold... |
| CVE-2026-4479 | MEDIUM | 4.4 | 0.2% | Apr 14, 2026 | The WholeSale Products Dynamic Pricing Management WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2026-4059 | MEDIUM | 6.4 | 0.3% | Apr 14, 2026 | The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the woolentor_quickview_button shor... |
| CVE-2026-1607 | MEDIUM | 6.4 | 0.2% | Apr 14, 2026 | The Surbma | Booking.com Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `s... |
| CVE-2026-34984 | MEDIUM | 6.5 | 0.3% | Apr 14, 2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete... |
| CVE-2026-39426 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS... |
| CVE-2026-39425 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS... |
| CVE-2026-34225 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.7.2 and be... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now