2026 CVE Vulnerabilities
50,889 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33005 | MEDIUM | 4.3 | 0.4% | Apr 9, 2026 | Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web se... |
| CVE-2026-4114 | MEDIUM | 6.6 | 0.6% | Apr 9, 2026 | Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin ... |
| CVE-2026-34757 | MEDIUM | 4.4 | 0.2% | Apr 9, 2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2026-3005 | MEDIUM | 6.4 | 0.3% | Apr 9, 2026 | The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' sho... |
| CVE-2026-2519 | MEDIUM | 5.3 | 0.5% | Apr 9, 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation v... |
| CVE-2026-24661 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which all... |
| CVE-2026-21388 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which all... |
| CVE-2026-4901 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker... |
| CVE-2026-34538 | MEDIUM | 6.5 | 0.7% | Apr 9, 2026 | Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have ... |
| CVE-2026-5848 | MEDIUM | 4.7 | 0.3% | Apr 9, 2026 | A vulnerability was found in jeecgboot JimuReport up to 2.3.0. The affected element is the function DriverManager.getCon... |
| CVE-2026-5847 | MEDIUM | 4.3 | 0.3% | Apr 9, 2026 | A vulnerability has been found in code-projects Movie Ticketing System 1.0. Impacted is an unknown function of the file ... |
| CVE-2026-5840 | MEDIUM | 4.7 | 0.2% | Apr 9, 2026 | A security flaw has been discovered in PHPGurukul News Portal Project 4.1. Impacted is an unknown function of the file /... |
| CVE-2026-5839 | MEDIUM | 4.7 | 0.2% | Apr 9, 2026 | A vulnerability was identified in PHPGurukul News Portal Project 4.1. This issue affects some unknown processing of the ... |
| CVE-2026-5838 | MEDIUM | 4.7 | 0.2% | Apr 9, 2026 | A vulnerability was determined in PHPGurukul News Portal Project 4.1. This vulnerability affects unknown code of the fil... |
| CVE-2026-5742 | MEDIUM | 6.4 | 0.2% | Apr 9, 2026 | The UsersWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.2.60. Th... |
| CVE-2026-4336 | MEDIUM | 6.4 | 0.2% | Apr 9, 2026 | The Ultimate FAQ Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via FAQ content in all vers... |
| CVE-2026-5833 | MEDIUM | 5.3 | 0.6% | Apr 9, 2026 | A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function serv... |
| CVE-2026-5357 | MEDIUM | 6.4 | 0.3% | Apr 9, 2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sid' parameter of the 'w... |
| CVE-2026-4429 | MEDIUM | 6.4 | 0.2% | Apr 9, 2026 | The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'marker_name' and 'fil... |
| CVE-2026-4124 | MEDIUM | 5.4 | 0.3% | Apr 9, 2026 | The Ziggeo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1. The ... |
| CVE-2026-3574 | MEDIUM | 4.4 | 0.2% | Apr 9, 2026 | The Experto Dashboard for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2026-3568 | MEDIUM | 4.3 | 0.2% | Apr 9, 2026 | The MStore API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includ... |
| CVE-2026-5831 | MEDIUM | 6.3 | 1.1% | Apr 9, 2026 | A security flaw has been discovered in Agions taskflow-ai up to 2.1.8. This impacts an unknown function of the file src/... |
| CVE-2026-5826 | MEDIUM | 4.3 | 0.4% | Apr 9, 2026 | A flaw has been found in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the... |
| CVE-2026-5825 | MEDIUM | 4.3 | 0.4% | Apr 9, 2026 | A vulnerability was detected in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now