2026 CVE Vulnerabilities
52,233 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5718 | HIGH | 8.1 | 4.2% | Apr 17, 2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in... |
| CVE-2026-5710 | HIGH | 7.5 | 0.7% | Apr 17, 2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading t... |
| CVE-2026-40320 | HIGH | 7.8 | 0.1% | Apr 17, 2026 | Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the ConformityCheck class rende... |
| CVE-2026-3464 | HIGH | 8.8 | 1.0% | Apr 17, 2026 | The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file pat... |
| CVE-2026-21733 | HIGH | 7.3 | 0.1% | Apr 17, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re... |
| CVE-2026-6490 | HIGH | 7.3 | 0.3% | Apr 17, 2026 | A weakness has been identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. Impacted is an unknown f... |
| CVE-2026-40459 | HIGH | 8.8 | 0.6% | Apr 17, 2026 | PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP synt... |
| CVE-2026-31317 | HIGH | 7.5 | 0.5% | Apr 17, 2026 | Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitr... |
| CVE-2026-6507 | HIGH | 7.5 | 0.5% | Apr 17, 2026 | A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially... |
| CVE-2026-6483 | HIGH | 7.3 | 14.1% | Apr 17, 2026 | A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the... |
| CVE-2026-23776 | HIGH | 8.8 | 0.2% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,... |
| CVE-2026-23778 | HIGH | 7.2 | 1.1% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,... |
| CVE-2026-40002 | HIGH | 8.8 | 0.1% | Apr 17, 2026 | Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operatio... |
| CVE-2026-33392 | HIGH | 7.2 | 0.4% | Apr 17, 2026 | In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass |
| CVE-2026-23853 | HIGH | 8.4 | 0.2% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,... |
| CVE-2026-4659 | HIGH | 7.5 | 0.9% | Apr 17, 2026 | The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV... |
| CVE-2026-6482 | HIGH | 7.8 | 0.2% | Apr 17, 2026 | The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to ... |
| CVE-2026-6421 | HIGH | 7 | 0.1% | Apr 17, 2026 | A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library... |
| CVE-2026-21719 | HIGH | 8.6 | 1.2% | Apr 17, 2026 | An OS command injection vulnerability exists in CubeCart prior to 6.6.0, which may allow a user with an administrative p... |
| CVE-2026-5807 | HIGH | 7.5 | 0.7% | Apr 17, 2026 | Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel... |
| CVE-2026-5052 | HIGH | 8.6 | 0.3% | Apr 17, 2026 | Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This ... |
| CVE-2026-4525 | HIGH | 8.8 | 0.4% | Apr 17, 2026 | If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used t... |
| CVE-2026-3605 | HIGH | 8.1 | 0.4% | Apr 17, 2026 | An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they w... |
| CVE-2026-5231 | HIGH | 7.2 | 0.5% | Apr 17, 2026 | The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in al... |
| CVE-2026-40262 | HIGH | 8.7 | 0.3% | Apr 17, 2026 | Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves upl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now