2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-89252 | MEDIUM | 6.5 | 0.2% | Sep 11, 2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updatin... |
| CVE-2026-89251 | MEDIUM | 6.5 | — | Sep 11, 2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.... |
| CVE-2026-89248 | MEDIUM | 5.3 | — | Sep 11, 2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugi... |
| CVE-2026-89247 | MEDIUM | 6.1 | 0.2% | Sep 11, 2026 | WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in pl... |
| CVE-2026-89246 | MEDIUM | 5.4 | — | Sep 11, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection vulnerability in th... |
| CVE-2026-89245 | MEDIUM | 6.5 | — | Sep 11, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability ... |
| CVE-2026-89244 | MEDIUM | 6.1 | — | Sep 11, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerabil... |
| CVE-2026-89241 | MEDIUM | 6.1 | — | Sep 11, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerabil... |
| CVE-2026-89240 | MEDIUM | 6.1 | — | Sep 11, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerabil... |
| CVE-2026-89239 | MEDIUM | 6.1 | — | Sep 11, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerabil... |
| CVE-2026-89148 | MEDIUM | 5.4 | — | Sep 11, 2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Be... |
| CVE-2026-86813 | MEDIUM | 4.8 | — | Sep 11, 2026 | The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that ... |
| CVE-2026-86809 | MEDIUM | 5.3 | — | Sep 11, 2026 | The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to i... |
| CVE-2026-85116 | MEDIUM | 6.5 | — | Sep 11, 2026 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over th... |
| CVE-2026-82215 | MEDIUM | 5.9 | — | Sep 11, 2026 | The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the pa... |
| CVE-2026-82213 | MEDIUM | 5.3 | — | Sep 11, 2026 | The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that the saved payment token being requested be... |
| CVE-2026-77159 | MEDIUM | 5.5 | 0.2% | Sep 11, 2026 | A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based ch... |
| CVE-2026-87859 | MEDIUM | 5.3 | 0.4% | Sep 11, 2026 | morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does n... |
| CVE-2026-87123 | MEDIUM | 5.9 | 0.3% | Sep 11, 2026 | hbs is an Express view engine wrapper for Handlebars. Version 4.3.0 can crash the Node.js process during output escaping... |
| CVE-2026-87727 | MEDIUM | 6.9 | 0.3% | Sep 11, 2026 | a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an unauthenticated attacker to ... |
| CVE-2026-89179 | MEDIUM | 4.3 | 0.1% | Sep 11, 2026 | WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerab... |
| CVE-2026-89175 | MEDIUM | 5.3 | 0.3% | Sep 11, 2026 | Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability... |
| CVE-2026-89173 | MEDIUM | 5.3 | 0.3% | Sep 11, 2026 | Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. U... |
| CVE-2026-6642 | MEDIUM | 6.4 | 0.2% | Sep 11, 2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset e... |
| CVE-2026-6641 | MEDIUM | 6.4 | — | Sep 11, 2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shor... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now