2026 CVE Vulnerabilities
50,629 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6034 | MEDIUM | 4.3 | 0.3% | Apr 10, 2026 | A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the fi... |
| CVE-2026-6033 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /updatedet... |
| CVE-2026-6032 | MEDIUM | 4.3 | 0.4% | Apr 10, 2026 | A vulnerability was found in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /chec... |
| CVE-2026-40212 | MEDIUM | 5.4 | 0.2% | Apr 10, 2026 | OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console... |
| CVE-2026-6030 | MEDIUM | 6.3 | 0.3% | Apr 10, 2026 | A flaw has been found in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of... |
| CVE-2026-4432 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_t... |
| CVE-2026-4482 | MEDIUM | 5.5 | 0.1% | Apr 10, 2026 | The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windo... |
| CVE-2026-6010 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | A security flaw has been discovered in CodeAstro Online Classroom 1.0/2.php. Affected by this vulnerability is an unknow... |
| CVE-2026-6007 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown function of the fi... |
| CVE-2026-6006 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | A vulnerability has been found in code-projects Patient Record Management System 1.0. The impacted element is an unknown... |
| CVE-2026-6005 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | A flaw has been found in code-projects Patient Record Management System 1.0. The affected element is an unknown function... |
| CVE-2026-5500 | MEDIUM | 5.9 | 0.4% | Apr 10, 2026 | wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication tag length received a... |
| CVE-2026-2305 | MEDIUM | 6.4 | 0.2% | Apr 10, 2026 | The AddFunc Head & Footer Code plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `aFhfc_head_cod... |
| CVE-2026-6000 | MEDIUM | 4.3 | 0.3% | Apr 10, 2026 | A vulnerability was found in code-projects Online Library Management System 1.0. Affected is an unknown function of the ... |
| CVE-2026-5999 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | A vulnerability has been found in JeecgBoot up to 3.9.1. This impacts an unknown function of the component SysAnnounceme... |
| CVE-2026-33551 | MEDIUM | 5.3 | 0.2% | Apr 10, 2026 | An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted applic... |
| CVE-2026-5998 | MEDIUM | 5.5 | 0.6% | Apr 10, 2026 | A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the file... |
| CVE-2026-4977 | MEDIUM | 4.3 | 0.3% | Apr 10, 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress is vulnerab... |
| CVE-2026-4664 | MEDIUM | 5.3 | 0.7% | Apr 10, 2026 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in all versions up to, ... |
| CVE-2026-4305 | MEDIUM | 6.1 | 0.3% | Apr 10, 2026 | The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the... |
| CVE-2026-4057 | MEDIUM | 4.3 | 0.4% | Apr 10, 2026 | The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2026-2712 | MEDIUM | 5.4 | 0.4% | Apr 10, 2026 | The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to missing capability che... |
| CVE-2026-1924 | MEDIUM | 4.3 | 0.2% | Apr 10, 2026 | The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2026-1263 | MEDIUM | 6.4 | 0.3% | Apr 10, 2026 | The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.9.... |
| CVE-2026-5460 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | A heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid KeyShare processing. In the err... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now