2026 CVE Vulnerabilities
64,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21092 | MEDIUM | 5.3 | 0.4% | Sep 9, 2026 | Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system s... |
| CVE-2026-21086 | MEDIUM | 4.8 | 0.1% | Sep 9, 2026 | Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configurat... |
| CVE-2026-21085 | MEDIUM | 6.7 | 0.1% | Sep 9, 2026 | Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out... |
| CVE-2026-19945 | MEDIUM | 6.4 | 0.2% | Sep 9, 2026 | The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in ... |
| CVE-2026-11821 | MEDIUM | 5.4 | 0.2% | Sep 9, 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to a... |
| CVE-2026-81647 | MEDIUM | 5.3 | 0.2% | Sep 9, 2026 | Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2026-81646 | MEDIUM | 5.9 | 0.1% | Sep 9, 2026 | Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2026-81644 | MEDIUM | 4.3 | 0.1% | Sep 9, 2026 | DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availa... |
| CVE-2026-7804 | MEDIUM | 6.1 | 0.3% | Sep 9, 2026 | The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '... |
| CVE-2026-77187 | MEDIUM | 6.4 | 0.2% | Sep 9, 2026 | The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'before... |
| CVE-2026-77186 | MEDIUM | 6.4 | 0.2% | Sep 9, 2026 | The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'fallba... |
| CVE-2026-75966 | MEDIUM | 6.4 | 0.3% | Sep 9, 2026 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'episode_contributor... |
| CVE-2026-57825 | MEDIUM | 5.7 | 0.3% | Sep 9, 2026 | In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishan... |
| CVE-2026-49313 | MEDIUM | 5.5 | 0.1% | Sep 9, 2026 | Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2026-49312 | MEDIUM | 4 | 0.1% | Sep 9, 2026 | Permission control vulnerability in the window module. Impact: Successful exploitation of this vulnerability may affect ... |
| CVE-2026-49311 | MEDIUM | 6.2 | 0.1% | Sep 9, 2026 | Permission control vulnerability in the event notification module.Impact: Successful exploitation of this vulnerability ... |
| CVE-2026-49309 | MEDIUM | 4.8 | 0.1% | Sep 9, 2026 | Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2026-41987 | MEDIUM | 6.2 | 0.1% | Sep 9, 2026 | Permission control vulnerability in the app management module. Impact: Successful exploitation of this vulnerability may... |
| CVE-2026-19944 | MEDIUM | 4.9 | 0.3% | Sep 9, 2026 | The WP Crowdfunding plugin for WordPress is vulnerable to generic SQL Injection via 'wpneo_reward' Post Meta in all vers... |
| CVE-2026-19800 | MEDIUM | 4.9 | 0.3% | Sep 9, 2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to... |
| CVE-2026-19797 | MEDIUM | 6.1 | 0.2% | Sep 9, 2026 | The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_group_section'... |
| CVE-2026-11363 | MEDIUM | 6.6 | 0.7% | Sep 9, 2026 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injectio... |
| CVE-2026-87073 | MEDIUM | 6.5 | 0.2% | Sep 9, 2026 | Tanium addressed an improper access controls vulnerability in Comply. |
| CVE-2026-87048 | MEDIUM | 5.4 | 0.2% | Sep 9, 2026 | Tanium addressed an improper access controls vulnerability in Comply. |
| CVE-2026-87047 | MEDIUM | 6.3 | 0.2% | Sep 9, 2026 | Tanium addressed an improper access controls vulnerability in Comply. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now