2026 CVE Vulnerabilities
64,751 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97527 | HIGH | 8.8 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize NVMe unsol ctx list with a... |
| CVE-2026-97525 | HIGH | 8.2 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Allocate split page tables as kernel pa... |
| CVE-2026-97524 | HIGH | 7.5 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid unneeded actions on subflow reset Onc... |
| CVE-2026-97523 | HIGH | 7.5 | — | Sep 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: mptcp: close race between scheduler and state chang... |
| CVE-2026-97898 | HIGH | 8.4 | — | Sep 25, 2026 | Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unloc... |
| CVE-2026-92560 | HIGH | 7.5 | — | Sep 25, 2026 | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential... |
| CVE-2026-92550 | HIGH | 7.5 | — | Sep 25, 2026 | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential... |
| CVE-2026-96752 | HIGH | 7.2 | — | Sep 25, 2026 | The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys... |
| CVE-2026-96568 | HIGH | 7.2 | — | Sep 25, 2026 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_n... |
| CVE-2026-95866 | HIGH | 7.2 | — | Sep 25, 2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2026-95864 | HIGH | 7.2 | — | Sep 25, 2026 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all ... |
| CVE-2026-94573 | HIGH | 7.2 | — | Sep 25, 2026 | The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater F... |
| CVE-2026-93901 | HIGH | 7.3 | — | Sep 25, 2026 | The Optima Express IDX plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, ... |
| CVE-2026-93654 | HIGH | 7.2 | — | Sep 25, 2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2026-92713 | HIGH | 8.1 | — | Sep 25, 2026 | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due ... |
| CVE-2026-92608 | HIGH | 7.5 | 0.2% | Sep 25, 2026 | Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated messa... |
| CVE-2026-89426 | HIGH | 8.8 | — | Sep 25, 2026 | The Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more plugin for WordPress is vulnerable to Privilege Escalation... |
| CVE-2026-89406 | HIGH | 7.5 | — | Sep 25, 2026 | The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized disclosure of p... |
| CVE-2026-84280 | HIGH | 7.2 | — | Sep 25, 2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Order 'elemen... |
| CVE-2026-19804 | HIGH | 8.8 | — | Sep 25, 2026 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin... |
| CVE-2026-13456 | HIGH | 7.5 | — | Sep 25, 2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnera... |
| CVE-2026-96039 | HIGH | 7.2 | — | Sep 25, 2026 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all... |
| CVE-2026-93303 | HIGH | 7.2 | — | Sep 25, 2026 | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cros... |
| CVE-2026-84281 | HIGH | 7.2 | — | Sep 25, 2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd... |
| CVE-2026-84279 | HIGH | 7.2 | — | Sep 25, 2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' par... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now