2026 CVE Vulnerabilities
51,046 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26070 | MEDIUM | 4.2 | 0.1% | Mar 26, 2026 | EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optiona... |
| CVE-2026-4877 | MEDIUM | 4.3 | 0.3% | Mar 26, 2026 | A security flaw has been discovered in itsourcecode Payroll Management System up to 1.0. This affects an unknown functio... |
| CVE-2026-4876 | MEDIUM | 6.3 | 0.2% | Mar 26, 2026 | A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown fun... |
| CVE-2026-33343 | MEDIUM | 6.5 | 0.2% | Mar 26, 2026 | etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9,... |
| CVE-2026-2389 | MEDIUM | 4.9 | 0.2% | Mar 26, 2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versio... |
| CVE-2026-1032 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | The Conditional Menus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2026-4875 | MEDIUM | 4.7 | 0.2% | Mar 26, 2026 | A vulnerability was determined in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown fun... |
| CVE-2026-4274 | MEDIUM | 5.4 | 0.1% | Mar 26, 2026 | Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-leve... |
| CVE-2026-23398 | MEDIUM | 5.5 | 0.1% | Mar 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: icmp: fix NULL pointer dereference in icmp_tag_vali... |
| CVE-2026-23396 | MEDIUM | 5.5 | 0.1% | Mar 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix NULL deref in mesh_matches_loca... |
| CVE-2026-4263 | MEDIUM | 6.9 | 0.3% | Mar 26, 2026 | Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other u... |
| CVE-2026-4262 | MEDIUM | 6.9 | 0.2% | Mar 26, 2026 | Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other u... |
| CVE-2026-4849 | MEDIUM | 6.1 | 0.3% | Mar 26, 2026 | A vulnerability was identified in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file ... |
| CVE-2026-4848 | MEDIUM | 4.3 | 0.3% | Mar 26, 2026 | A vulnerability was determined in dameng100 muucmf 1.9.5.20260309. This affects an unknown function of the file /admin/e... |
| CVE-2026-4847 | MEDIUM | 4.3 | 0.3% | Mar 26, 2026 | A vulnerability was found in dameng100 muucmf 1.9.5.20260309. The impacted element is an unknown function of the file /a... |
| CVE-2026-1890 | MEDIUM | 5.3 | 0.2% | Mar 26, 2026 | The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated u... |
| CVE-2026-1430 | MEDIUM | 4.8 | 0.2% | Mar 26, 2026 | The WP Lightbox 2 WordPress plugin before 3.0.7 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2026-4846 | MEDIUM | 4.3 | 0.3% | Mar 26, 2026 | A vulnerability has been found in dameng100 muucmf 1.9.5.20260309. The affected element is an unknown function of the fi... |
| CVE-2026-4845 | MEDIUM | 4.3 | 0.3% | Mar 26, 2026 | A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is an unknown function of the file /admin/Member/inde... |
| CVE-2026-1206 | MEDIUM | 4.3 | 0.3% | Mar 26, 2026 | The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exp... |
| CVE-2026-4389 | MEDIUM | 6.4 | 0.2% | Mar 26, 2026 | The DSGVO snippet for Leaflet Map and its Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2026-4331 | MEDIUM | 4.3 | 0.2% | Mar 26, 2026 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized data loss in all ... |
| CVE-2026-4281 | MEDIUM | 5.3 | 0.5% | Mar 26, 2026 | The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up t... |
| CVE-2026-4278 | MEDIUM | 6.4 | 0.2% | Mar 26, 2026 | The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortco... |
| CVE-2026-4335 | MEDIUM | 5.4 | 0.2% | Mar 26, 2026 | The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment post... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now