2026 CVE Vulnerabilities
50,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5867 | MEDIUM | 4.3 | 0.3% | Apr 8, 2026 | Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially se... |
| CVE-2026-5864 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Heap buffer overflow in WebAudio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially... |
| CVE-2026-5808 | MEDIUM | 5.3 | 0.3% | Apr 8, 2026 | A vulnerability was detected in openstatusHQ openstatus up to 1b678e71a85961ae319cbb214a8eae634059330c. This impacts an ... |
| CVE-2026-5711 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The Post Blocks & Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sliderStyle' block at... |
| CVE-2026-40028 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | Hayabusa versions prior to 3.8.0 contain a cross-site scripting (XSS) vulnerability in its HTML report output that allow... |
| CVE-2026-40025 | MEDIUM | 6.1 | 0.1% | Apr 8, 2026 | The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where th... |
| CVE-2026-39901 | MEDIUM | 5.7 | 0.3% | Apr 8, 2026 | monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity f... |
| CVE-2026-5803 | MEDIUM | 6.3 | 0.2% | Apr 8, 2026 | A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The aff... |
| CVE-2026-5451 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'elevation-trac... |
| CVE-2026-39882 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/log... |
| CVE-2026-39416 | MEDIUM | 6.1 | 0.2% | Apr 8, 2026 | AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a store... |
| CVE-2026-39415 | MEDIUM | 4.3 | 0.3% | Apr 8, 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.46.0, ... |
| CVE-2026-39414 | MEDIUM | 6.5 | 0.5% | Apr 8, 2026 | MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-... |
| CVE-2026-39880 | MEDIUM | 4.9 | 0.2% | Apr 8, 2026 | Remnawave Backend is the backend for the Remnawave proxy and user management solution. Prior to 2.7.5, a glitch in the H... |
| CVE-2026-39864 | MEDIUM | 4.9 | 0.3% | Apr 8, 2026 | Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in ... |
| CVE-2026-39413 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.4.14, the LightRAG API is vulnerable to a J... |
| CVE-2026-35479 | MEDIUM | 4.7 | 0.2% | Apr 8, 2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permi... |
| CVE-2026-35476 | MEDIUM | 4.3 | 0.1% | Apr 8, 2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can el... |
| CVE-2026-39851 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange... |
| CVE-2026-35455 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripti... |
| CVE-2026-35407 | MEDIUM | 6.5 | 0.3% | Apr 8, 2026 | Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a business-logic and a... |
| CVE-2026-35403 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-35400 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-35169 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-35165 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now