2026 CVE Vulnerabilities
50,938 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33227 | MEDIUM | 4.3 | 0.4% | Apr 7, 2026 | Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ... |
| CVE-2026-3177 | MEDIUM | 5.3 | 0.2% | Apr 7, 2026 | The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul... |
| CVE-2026-4079 | MEDIUM | 6.5 | 0.2% | Apr 7, 2026 | The SQL Chart Builder WordPress plugin before 2.3.8 does not properly escape user input as it is concatened to SQL queri... |
| CVE-2026-1900 | MEDIUM | 6.5 | 0.2% | Apr 7, 2026 | The Link Whisper Free WordPress plugin before 0.9.1 has a publicly accessible REST endpoint that allows unauthenticated ... |
| CVE-2026-20446 | MEDIUM | 4.3 | 0.2% | Apr 7, 2026 | In sec boot, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of serv... |
| CVE-2026-20431 | MEDIUM | 6.5 | 0.3% | Apr 7, 2026 | In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE ha... |
| CVE-2026-5719 | MEDIUM | 6.3 | 0.2% | Apr 7, 2026 | A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /... |
| CVE-2026-5705 | MEDIUM | 4.3 | 0.4% | Apr 7, 2026 | A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown f... |
| CVE-2026-35475 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, the redirect parameter is taken directly from $_GET ... |
| CVE-2026-35474 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, open redirect has been found in WeGIA webapp. The re... |
| CVE-2026-35473 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the... |
| CVE-2026-35454 | MEDIUM | 6.5 | 0.3% | Apr 6, 2026 | The Code Extension Marketplace is an open-source alternative to the VS Code Marketplace. Prior to 2.4.2, Zip Slip vulner... |
| CVE-2026-35452 | MEDIUM | 5.3 | 0.4% | Apr 6, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint s... |
| CVE-2026-35450 | MEDIUM | 5.3 | 0.4% | Apr 6, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint ... |
| CVE-2026-35449 | MEDIUM | 5.3 | 0.3% | Apr 6, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its... |
| CVE-2026-35444 | MEDIUM | 6.1 | 0.3% | Apr 6, 2026 | SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel ... |
| CVE-2026-35441 | MEDIUM | 6.5 | 0.4% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL end... |
| CVE-2026-35413 | MEDIUM | 5.3 | 0.3% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPE... |
| CVE-2026-35411 | MEDIUM | 4.3 | 0.3% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerabl... |
| CVE-2026-35410 | MEDIUM | 6.1 | 0.3% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vuln... |
| CVE-2026-35404 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a... |
| CVE-2026-22675 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | OCS Inventory NG Server version 2.12.3 and prior contain a stored cross-site scripting vulnerability that allows unauthe... |
| CVE-2026-35472 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the... |
| CVE-2026-35399 | MEDIUM | 6.1 | 0.3% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, a stored XSS vulnerability allows an attacker to inj... |
| CVE-2026-35398 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now