2026 CVE Vulnerabilities
50,981 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21631 | MEDIUM | 5.4 | 0.2% | Apr 1, 2026 | Lack of output escaping leads to a XSS vector in the multilingual associations component. |
| CVE-2026-1879 | MEDIUM | 6.3 | 0.3% | Apr 1, 2026 | A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the fil... |
| CVE-2026-34889 | MEDIUM | 6.5 | 0.2% | Apr 1, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force U... |
| CVE-2026-23409 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix differential encoding verification D... |
| CVE-2026-23405 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix: limit the number of levels of policy... |
| CVE-2026-23404 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: replace recursive profile removal with it... |
| CVE-2026-23403 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix memory leak in verify_header The fun... |
| CVE-2026-23402 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Only WARN in direct MMUs when overwri... |
| CVE-2026-23401 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Drop/zap existing present SPTE even w... |
| CVE-2026-5259 | MEDIUM | 6.3 | 0.2% | Apr 1, 2026 | A vulnerability was determined in AutohomeCorp frostmourne up to 1.0. The affected element is an unknown function of the... |
| CVE-2026-5255 | MEDIUM | 6.1 | 0.3% | Apr 1, 2026 | A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delst... |
| CVE-2026-2696 | MEDIUM | 5.3 | 0.3% | Apr 1, 2026 | The Export All URLs WordPress plugin before 5.1 generates CSV filenames containing posts URLS (including private posts) ... |
| CVE-2026-5291 | MEDIUM | 6.5 | 0.2% | Apr 1, 2026 | Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain poten... |
| CVE-2026-5283 | MEDIUM | 6.5 | 0.2% | Apr 1, 2026 | Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-o... |
| CVE-2026-5276 | MEDIUM | 6.5 | 0.2% | Apr 1, 2026 | Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain p... |
| CVE-2026-5273 | MEDIUM | 6.3 | 0.3% | Apr 1, 2026 | Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code insid... |
| CVE-2026-5251 | MEDIUM | 6.3 | 0.2% | Apr 1, 2026 | A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user... |
| CVE-2026-3831 | MEDIUM | 4.3 | 0.2% | Apr 1, 2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of d... |
| CVE-2026-3778 | MEDIUM | 5.5 | 0.1% | Apr 1, 2026 | The application does not detect or guard against cyclic PDF object references while handling JavaScript in PDF. When pag... |
| CVE-2026-3776 | MEDIUM | 5.5 | 0.1% | Apr 1, 2026 | The application does not validate the presence of required appearance (AP) data before accessing stamp annotation resour... |
| CVE-2026-5248 | MEDIUM | 6.3 | 0.2% | Apr 1, 2026 | A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app... |
| CVE-2026-35057 | MEDIUM | 5.4 | 0.2% | Apr 1, 2026 | XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, ... |
| CVE-2026-35055 | MEDIUM | 6.1 | 0.2% | Apr 1, 2026 | XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. A... |
| CVE-2026-35054 | MEDIUM | 5.4 | 0.1% | Apr 1, 2026 | XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can in... |
| CVE-2026-2394 | MEDIUM | 6.5 | 0.2% | Apr 1, 2026 | Buffer Over-read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects C... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now