2026 CVE Vulnerabilities
64,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90553 | HIGH | 7.8 | 0.2% | Sep 12, 2026 | vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores t... |
| CVE-2026-90537 | HIGH | 8.2 | 0.2% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in pl... |
| CVE-2026-90535 | HIGH | 7.5 | 0.2% | Sep 12, 2026 | Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/a... |
| CVE-2026-15451 | HIGH | 8.8 | 0.2% | Sep 12, 2026 | The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and inc... |
| CVE-2026-85200 | HIGH | 7.5 | 0.8% | Sep 12, 2026 | The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 v... |
| CVE-2026-78175 | HIGH | 8.8 | 0.6% | Sep 12, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all v... |
| CVE-2026-16482 | HIGH | 7.5 | 0.3% | Sep 12, 2026 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection v... |
| CVE-2026-87888 | HIGH | 8 | 0.2% | Sep 12, 2026 | The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pri... |
| CVE-2026-87842 | HIGH | 7.5 | 0.3% | Sep 12, 2026 | The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the s... |
| CVE-2026-87759 | HIGH | 8.8 | 0.2% | Sep 12, 2026 | The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a p... |
| CVE-2026-84099 | HIGH | 8.1 | 0.3% | Sep 12, 2026 | The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that ... |
| CVE-2026-84047 | HIGH | 8.6 | 0.3% | Sep 12, 2026 | The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it ... |
| CVE-2026-81742 | HIGH | 8.8 | 0.3% | Sep 12, 2026 | The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to... |
| CVE-2026-81429 | HIGH | 7.1 | 0.1% | Sep 12, 2026 | The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template... |
| CVE-2026-81090 | HIGH | 7.2 | 0.3% | Sep 12, 2026 | The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the... |
| CVE-2026-80494 | HIGH | 8.6 | 0.3% | Sep 12, 2026 | The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file... |
| CVE-2026-80491 | HIGH | 8.6 | 0.3% | Sep 12, 2026 | The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL qu... |
| CVE-2026-77752 | HIGH | 7.2 | 0.3% | Sep 12, 2026 | The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary ... |
| CVE-2026-77705 | HIGH | 7.2 | 0.3% | Sep 12, 2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a... |
| CVE-2026-89266 | HIGH | 8.2 | 0.6% | Sep 12, 2026 | stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation s... |
| CVE-2026-90460 | HIGH | 7.6 | 0.3% | Sep 11, 2026 | An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 c... |
| CVE-2026-90451 | HIGH | 8.2 | 0.3% | Sep 11, 2026 | An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication co... |
| CVE-2026-90448 | HIGH | 7.1 | 0.2% | Sep 11, 2026 | A deployment mode intended to expose only read access to stored data proxies a set of application programming interface ... |
| CVE-2026-90447 | HIGH | 7.1 | 0.3% | Sep 11, 2026 | A routing rule selects between two different authentication mechanisms for the same downstream service based on the valu... |
| CVE-2026-90445 | HIGH | 7.1 | 0.3% | Sep 11, 2026 | An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without valid... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now