2026 CVE Vulnerabilities
50,938 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39935 | MEDIUM | 6.9 | 0.3% | Apr 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun... |
| CVE-2026-4065 | MEDIUM | 5.4 | 0.4% | Apr 7, 2026 | The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing cap... |
| CVE-2026-39934 | MEDIUM | 6.9 | 0.3% | Apr 7, 2026 | Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExper... |
| CVE-2026-39933 | MEDIUM | 6.9 | 0.3% | Apr 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun... |
| CVE-2026-35568 | MEDIUM | 5.7 | 0.1% | Apr 7, 2026 | MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk conta... |
| CVE-2026-34371 | MEDIUM | 6.3 | 0.3% | Apr 7, 2026 | LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e... |
| CVE-2026-39401 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processe... |
| CVE-2026-39400 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, a non-admin user ... |
| CVE-2026-34080 | MEDIUM | 5.5 | 0.2% | Apr 7, 2026 | xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassin... |
| CVE-2026-32712 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to ... |
| CVE-2026-27949 | MEDIUM | 4.3 | 0.2% | Apr 7, 2026 | Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentica... |
| CVE-2026-39841 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Medi... |
| CVE-2026-39840 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundati... |
| CVE-2026-39839 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Medi... |
| CVE-2026-39838 | MEDIUM | 6.9 | 0.4% | Apr 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundati... |
| CVE-2026-39837 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Car... |
| CVE-2026-39395 | MEDIUM | 5.3 | 0.2% | Apr 7, 2026 | Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-... |
| CVE-2026-39381 | MEDIUM | 4.3 | 0.2% | Apr 7, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-a... |
| CVE-2026-39380 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to ... |
| CVE-2026-39373 | MEDIUM | 5.3 | 0.3% | Apr 7, 2026 | JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attac... |
| CVE-2026-39368 | MEDIUM | 6.5 | 0.2% | Apr 7, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted a... |
| CVE-2026-39367 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) featur... |
| CVE-2026-39366 | MEDIUM | 6.5 | 0.2% | Apr 7, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/... |
| CVE-2026-39365 | MEDIUM | 5.3 | 0.9% | Apr 7, 2026 | Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s hand... |
| CVE-2026-5762 | MEDIUM | 5.3 | 0.3% | Apr 7, 2026 | Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Ex... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now