2026 CVE Vulnerabilities
64,868 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-78172 | MEDIUM | 6.1 | 0.2% | Sep 11, 2026 | The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query ... |
| CVE-2026-77150 | MEDIUM | 6.1 | 0.3% | Sep 11, 2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name... |
| CVE-2026-19985 | MEDIUM | 6.1 | 0.3% | Sep 11, 2026 | The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to,... |
| CVE-2026-18964 | MEDIUM | 6.1 | — | Sep 11, 2026 | The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plu... |
| CVE-2026-18562 | MEDIUM | 6.1 | 0.2% | Sep 11, 2026 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scri... |
| CVE-2026-12215 | MEDIUM | 5.3 | — | Sep 11, 2026 | The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in ... |
| CVE-2026-11496 | MEDIUM | 6.5 | 0.3% | Sep 11, 2026 | The Woo PDF Invoice Builder plugin (also distributed as "PDF Builder for WooCommerce") for WordPress is vulnerable to In... |
| CVE-2026-11446 | MEDIUM | 5.3 | 0.2% | Sep 11, 2026 | The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2026-89145 | MEDIUM | 4.2 | 0.2% | Sep 11, 2026 | Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error pag... |
| CVE-2026-89092 | MEDIUM | 4.2 | 0.2% | Sep 11, 2026 | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server retur... |
| CVE-2026-88914 | MEDIUM | 4.4 | 0.1% | Sep 11, 2026 | A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file cont... |
| CVE-2026-78129 | MEDIUM | 5.9 | 0.4% | Sep 11, 2026 | strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption. |
| CVE-2026-78126 | MEDIUM | 5.9 | 0.4% | Sep 11, 2026 | strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin. |
| CVE-2026-78123 | MEDIUM | 5.9 | 0.4% | Sep 11, 2026 | strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin. |
| CVE-2026-84941 | MEDIUM | 6.9 | 0.3% | Sep 11, 2026 | An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an aut... |
| CVE-2026-81906 | MEDIUM | 6.3 | 0.3% | Sep 11, 2026 | Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-valid... |
| CVE-2026-81905 | MEDIUM | 6.3 | 0.2% | Sep 11, 2026 | Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password re... |
| CVE-2026-18121 | MEDIUM | 6.3 | 0.3% | Sep 11, 2026 | Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endp... |
| CVE-2026-16172 | MEDIUM | 6 | 0.1% | Sep 10, 2026 | Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A... |
| CVE-2026-86087 | MEDIUM | 4.3 | 0.2% | Sep 10, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted r... |
| CVE-2026-82100 | MEDIUM | 6.5 | 0.4% | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due... |
| CVE-2026-82092 | MEDIUM | 6.5 | 0.5% | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ... |
| CVE-2026-81554 | MEDIUM | 6.5 | 0.5% | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ... |
| CVE-2026-80434 | MEDIUM | 5 | 0.2% | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and... |
| CVE-2026-80378 | MEDIUM | 6.5 | 0.3% | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now