2026 CVE Vulnerabilities
64,868 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-89179 | MEDIUM | 4.3 | 0.1% | Sep 11, 2026 | WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerab... |
| CVE-2026-89175 | MEDIUM | 5.3 | 0.3% | Sep 11, 2026 | Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability... |
| CVE-2026-89173 | MEDIUM | 5.3 | 0.3% | Sep 11, 2026 | Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. U... |
| CVE-2026-6642 | MEDIUM | 6.4 | 0.2% | Sep 11, 2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset e... |
| CVE-2026-6641 | MEDIUM | 6.4 | — | Sep 11, 2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shor... |
| CVE-2026-6640 | MEDIUM | 6.4 | — | Sep 11, 2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attribut... |
| CVE-2026-86815 | MEDIUM | 5.5 | 0.2% | Sep 11, 2026 | The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job,... |
| CVE-2026-86812 | MEDIUM | 6.5 | 0.2% | Sep 11, 2026 | The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoint... |
| CVE-2026-86782 | MEDIUM | 5.5 | 0.2% | Sep 11, 2026 | The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing... |
| CVE-2026-86781 | MEDIUM | 5.3 | 0.1% | Sep 11, 2026 | The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or ... |
| CVE-2026-86780 | MEDIUM | 6.8 | 0.2% | Sep 11, 2026 | The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value be... |
| CVE-2026-85678 | MEDIUM | 6.8 | 0.2% | Sep 11, 2026 | The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it... |
| CVE-2026-83546 | MEDIUM | 6.8 | 0.2% | Sep 11, 2026 | The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML ... |
| CVE-2026-83545 | MEDIUM | 6.8 | 0.2% | Sep 11, 2026 | The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside a... |
| CVE-2026-82305 | MEDIUM | 5.3 | 0.1% | Sep 11, 2026 | The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given... |
| CVE-2026-14566 | MEDIUM | 4.3 | 0.1% | Sep 11, 2026 | The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce chec... |
| CVE-2026-14565 | MEDIUM | 5.4 | 0.2% | Sep 11, 2026 | The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce chec... |
| CVE-2026-14562 | MEDIUM | 5.3 | 0.1% | Sep 11, 2026 | The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks bef... |
| CVE-2026-13326 | MEDIUM | 6.9 | 0.2% | Sep 11, 2026 | An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial ... |
| CVE-2026-89169 | MEDIUM | 4.1 | 0.1% | Sep 11, 2026 | live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .ver... |
| CVE-2026-89160 | MEDIUM | 6.5 | 0.2% | Sep 11, 2026 | PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF su... |
| CVE-2026-89158 | MEDIUM | 6.5 | 0.2% | Sep 11, 2026 | PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write. |
| CVE-2026-89156 | MEDIUM | 5.9 | 0.1% | Sep 11, 2026 | PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF da... |
| CVE-2026-84960 | MEDIUM | 6.1 | 0.2% | Sep 11, 2026 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query Stri... |
| CVE-2026-7438 | MEDIUM | 6.4 | — | Sep 11, 2026 | The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subti... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now