2026 CVE Vulnerabilities
50,954 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5528 | MEDIUM | 6.3 | 1.5% | Apr 5, 2026 | A security vulnerability has been detected in MoussaabBadla code-screenshot-mcp up to 0.1.0. This affects an unknown par... |
| CVE-2026-5527 | MEDIUM | 5.5 | 0.4% | Apr 5, 2026 | A weakness has been identified in Tenda 4G03 Pro 1.0/1.0re/01.bin/04.03.01.53. Affected by this issue is some unknown fu... |
| CVE-2026-3309 | MEDIUM | 6.5 | 0.4% | Apr 4, 2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres... |
| CVE-2026-0626 | MEDIUM | 6.4 | 0.2% | Apr 4, 2026 | The WPFunnels – Easy Funnel Builder To Optimize Buyer Journeys And Get More Leads & Sales plugin for WordPress is vulner... |
| CVE-2026-2826 | MEDIUM | 4.3 | 0.3% | Apr 4, 2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypas... |
| CVE-2026-2437 | MEDIUM | 6.4 | 0.2% | Apr 4, 2026 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2026-2600 | MEDIUM | 6.4 | 0.3% | Apr 4, 2026 | The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2026-0738 | MEDIUM | 6.4 | 0.3% | Apr 4, 2026 | The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2026-0737 | MEDIUM | 6.4 | 0.3% | Apr 4, 2026 | The WP Shortcodes Plugin - Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ... |
| CVE-2026-0664 | MEDIUM | 6.4 | 0.3% | Apr 4, 2026 | The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button_text' p... |
| CVE-2026-0552 | MEDIUM | 6.4 | 0.2% | Apr 4, 2026 | The Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsc_displa... |
| CVE-2026-2949 | MEDIUM | 6.4 | 0.2% | Apr 4, 2026 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the I... |
| CVE-2026-2924 | MEDIUM | 6.4 | 0.2% | Apr 4, 2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Sit... |
| CVE-2026-3571 | MEDIUM | 6.5 | 0.3% | Apr 4, 2026 | The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized ... |
| CVE-2026-34780 | MEDIUM | 6.1 | 0.3% | Apr 4, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From versions 39... |
| CVE-2026-34778 | MEDIUM | 6.5 | 0.1% | Apr 4, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version... |
| CVE-2026-34777 | MEDIUM | 5.4 | 0.1% | Apr 4, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version... |
| CVE-2026-34776 | MEDIUM | 5.3 | 0.2% | Apr 4, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version... |
| CVE-2026-34767 | MEDIUM | 6.5 | 0.2% | Apr 4, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version... |
| CVE-2026-34766 | MEDIUM | 5.4 | 0.2% | Apr 4, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version... |
| CVE-2026-34933 | MEDIUM | 5.5 | 0.2% | Apr 3, 2026 | Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to ve... |
| CVE-2026-34788 | MEDIUM | 6.5 | 0.3% | Apr 3, 2026 | Emlog is an open source website building system. In versions 2.6.2 and prior, a SQL injection vulnerability exists in in... |
| CVE-2026-34787 | MEDIUM | 6.5 | 0.5% | Apr 3, 2026 | Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability... |
| CVE-2026-34229 | MEDIUM | 6.1 | 0.2% | Apr 3, 2026 | Emlog is an open source website building system. Prior to version 2.6.8, there is a stored cross-site scripting (XSS) vu... |
| CVE-2026-34228 | MEDIUM | 6.5 | 0.2% | Apr 3, 2026 | Emlog is an open source website building system. Prior to version 2.6.8, the backend upgrade interface accepts remote SQ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now