2026 CVE Vulnerabilities
50,971 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23419 | MEDIUM | 5.5 | 0.2% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/rds: Fix circular locking dependency in rds_tcp... |
| CVE-2026-23418 | MEDIUM | 5.5 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/reg_sr: Fix leak on xa_store failure Free t... |
| CVE-2026-27655 | MEDIUM | 4.8 | 0.5% | Apr 3, 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on M... |
| CVE-2026-5467 | MEDIUM | 6.1 | 0.3% | Apr 3, 2026 | A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component... |
| CVE-2026-4108 | MEDIUM | 4.8 | 0.5% | Apr 3, 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Perm... |
| CVE-2026-4107 | MEDIUM | 5.4 | 0.5% | Apr 3, 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count a... |
| CVE-2026-3880 | MEDIUM | 4.8 | 0.5% | Apr 3, 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client P... |
| CVE-2026-3879 | MEDIUM | 4.8 | 0.5% | Apr 3, 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Deta... |
| CVE-2026-28703 | MEDIUM | 4.8 | 0.5% | Apr 3, 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Betwee... |
| CVE-2026-28756 | MEDIUM | 4.8 | 0.5% | Apr 3, 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on D... |
| CVE-2026-28754 | MEDIUM | 4.8 | 0.5% | Apr 3, 2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists rep... |
| CVE-2026-35549 | MEDIUM | 6.5 | 0.3% | Apr 3, 2026 | An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. I... |
| CVE-2026-35544 | MEDIUM | 5.3 | 0.4% | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitiz... |
| CVE-2026-35543 | MEDIUM | 5.3 | 0.4% | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed... |
| CVE-2026-35542 | MEDIUM | 5.3 | 0.4% | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed... |
| CVE-2026-35541 | MEDIUM | 4.2 | 0.2% | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plu... |
| CVE-2026-35540 | MEDIUM | 6.5 | 0.3% | Apr 3, 2026 | An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization... |
| CVE-2026-35539 | MEDIUM | 6.1 | 0.3% | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachmen... |
| CVE-2026-35536 | MEDIUM | 5.3 | 0.2% | Apr 3, 2026 | In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .Req... |
| CVE-2026-35508 | MEDIUM | 6.1 | 0.2% | Apr 3, 2026 | Shynet before 0.14.0 allows XSS in urldisplay and iconify template filters, |
| CVE-2026-35507 | MEDIUM | 6.5 | 0.1% | Apr 3, 2026 | Shynet before 0.14.0 allows Host header injection in the password reset flow. |
| CVE-2026-35466 | MEDIUM | 6.1 | 0.2% | Apr 2, 2026 | XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from C... |
| CVE-2026-30252 | MEDIUM | 6.1 | 0.2% | Apr 2, 2026 | Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l Zen... |
| CVE-2026-30251 | MEDIUM | 6.1 | 0.2% | Apr 2, 2026 | A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenSh... |
| CVE-2026-35383 | MEDIUM | 6.9 | 0.3% | Apr 2, 2026 | Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated att... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now