2026 CVE Vulnerabilities
64,889 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86777 | MEDIUM | 5.3 | 0.4% | Sep 9, 2026 | AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing... |
| CVE-2026-86547 | MEDIUM | 6.2 | 0.1% | Sep 9, 2026 | mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when proces... |
| CVE-2026-78377 | MEDIUM | 6.1 | 0.2% | Sep 9, 2026 | URL redirection to untrusted site ('open redirect') vulnerability in Yordam Informatics Technology Consulting, Training,... |
| CVE-2026-19733 | MEDIUM | 5.3 | 0.2% | Sep 9, 2026 | Server-Side request forgery (SSRF) vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic S... |
| CVE-2026-11838 | MEDIUM | 4.3 | 0.3% | Sep 9, 2026 | Missing authentication for critical function vulnerability in Yordam Informatics Technology Consulting, Training, and El... |
| CVE-2026-79974 | MEDIUM | 6.4 | 0.2% | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-79973 | MEDIUM | 6.3 | 0.1% | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-79967 | MEDIUM | 5.6 | 0.1% | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-79640 | MEDIUM | 5.4 | 0.1% | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-80177 | MEDIUM | 6.5 | 0.2% | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-80124 | MEDIUM | 5.5 | 0.1% | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-80055 | MEDIUM | 4.4 | 0.2% | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-19778 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | The WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping plugin for WordPress is vulnera... |
| CVE-2026-19729 | MEDIUM | 4.9 | 0.5% | Sep 9, 2026 | A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Ha... |
| CVE-2026-17149 | MEDIUM | 6.4 | 0.2% | Sep 9, 2026 | The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress ... |
| CVE-2026-15398 | MEDIUM | 4.3 | 0.3% | Sep 9, 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to a... |
| CVE-2026-87747 | MEDIUM | 4.9 | 0.4% | Sep 9, 2026 | The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers c... |
| CVE-2026-85117 | MEDIUM | 6.5 | 0.2% | Sep 9, 2026 | The Contact Form 7 Captcha WordPress plugin before 0.1.9 runs the shortcode parser over the whole rendered Contact Form ... |
| CVE-2026-83537 | MEDIUM | 5.3 | 0.1% | Sep 9, 2026 | The WP Express Checkout WordPress plugin before 2.5.0 does not verify server-side that a payment was actually completed ... |
| CVE-2026-80440 | MEDIUM | 4.8 | 0.2% | Sep 9, 2026 | The Hustle WordPress plugin before 7.8.14.2 does not prevent shortcodes in submitted form values from being executed whe... |
| CVE-2026-19855 | MEDIUM | 6.5 | 0.2% | Sep 9, 2026 | The CleanTalk WordPress plugin before 6.87 does not prevent unauthenticated, user-supplied comment content from being pa... |
| CVE-2026-19802 | MEDIUM | 4.3 | 0.3% | Sep 9, 2026 | The Checkout Custom Fields Builder for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all ver... |
| CVE-2026-8615 | MEDIUM | 4.3 | 0.2% | Sep 9, 2026 | The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2026-85418 | MEDIUM | 5.4 | 0.2% | Sep 9, 2026 | The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.9... |
| CVE-2026-85133 | MEDIUM | 5.4 | 0.1% | Sep 9, 2026 | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not perform nonce or capability checks on several of its set... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now