2026 CVE Vulnerabilities
50,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39392 | MEDIUM | 4.8 | 0.2% | Apr 8, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-39391 | MEDIUM | 4.8 | 0.2% | Apr 8, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-39390 | MEDIUM | 4.8 | 0.2% | Apr 8, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-35023 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the previ... |
| CVE-2026-31411 | MEDIUM | 5.5 | 0.1% | Apr 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer ... |
| CVE-2026-2509 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Cu... |
| CVE-2026-5600 | MEDIUM | 4.3 | 0.3% | Apr 8, 2026 | A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact... |
| CVE-2026-5301 | MEDIUM | 6.1 | 0.3% | Apr 8, 2026 | Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the serv... |
| CVE-2026-28261 | MEDIUM | 5.5 | 0.1% | Apr 8, 2026 | Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0... |
| CVE-2026-24511 | MEDIUM | 4.4 | 0.2% | Apr 8, 2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation o... |
| CVE-2026-2481 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site ... |
| CVE-2026-28264 | MEDIUM | 5.5 | 0.1% | Apr 8, 2026 | Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission Assignment for Critical Re... |
| CVE-2026-1865 | MEDIUM | 6.5 | 0.3% | Apr 8, 2026 | The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U... |
| CVE-2026-1673 | MEDIUM | 4.3 | 0.1% | Apr 8, 2026 | The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnera... |
| CVE-2026-1672 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnera... |
| CVE-2026-4303 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2026-4300 | MEDIUM | 6.4 | 0.4% | Apr 8, 2026 | The Robo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Loading Label' setting in al... |
| CVE-2026-4073 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The pdfl.io plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pdflio' shortcode in all versions... |
| CVE-2026-4025 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The PrivateContent Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' shortcode attr... |
| CVE-2026-39716 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in CKThemes Flipmart flipmart allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2026-39715 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in AnyTrack AnyTrack Affiliate Link Manager anytrack-affiliate-link-manager allows E... |
| CVE-2026-39714 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in G5Theme G5Plus April g5plus-april allows Exploiting Incorrectly Configured Access... |
| CVE-2026-39713 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Missing Authorization vulnerability in mailercloud Mailercloud – Integrate webforms and synchronize website contacts mai... |
| CVE-2026-39712 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in tagDiv tagDiv Composer td... |
| CVE-2026-39711 | MEDIUM | 5.3 | 0.3% | Apr 8, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allow... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now