2026 CVE Vulnerabilities
64,982 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86217 | MEDIUM | 5.3 | 0.3% | Sep 6, 2026 | A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function ... |
| CVE-2026-86216 | MEDIUM | 4.3 | 0.3% | Sep 6, 2026 | A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an un... |
| CVE-2026-86215 | MEDIUM | 4.3 | 0.2% | Sep 6, 2026 | A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the... |
| CVE-2026-86258 | MEDIUM | 5.9 | 0.4% | Sep 6, 2026 | nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix co... |
| CVE-2026-86257 | MEDIUM | 5.4 | 0.2% | Sep 6, 2026 | wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gy... |
| CVE-2026-86256 | MEDIUM | 5.4 | 0.2% | Sep 6, 2026 | wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/cor... |
| CVE-2026-86255 | MEDIUM | 6.5 | 0.2% | Sep 6, 2026 | wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create ro... |
| CVE-2026-86254 | MEDIUM | 6.8 | 0.2% | Sep 6, 2026 | wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views ret... |
| CVE-2026-86253 | MEDIUM | 5.9 | 0.4% | Sep 6, 2026 | h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments... |
| CVE-2026-86252 | MEDIUM | 5.3 | 0.2% | Sep 6, 2026 | h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing a... |
| CVE-2026-86251 | MEDIUM | 5.9 | 0.3% | Sep 6, 2026 | h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allo... |
| CVE-2026-86212 | MEDIUM | 4.3 | 0.3% | Sep 6, 2026 | A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME.... |
| CVE-2026-86205 | MEDIUM | 5.4 | 0.2% | Sep 6, 2026 | h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to saniti... |
| CVE-2026-80439 | MEDIUM | 4.8 | 0.2% | Sep 6, 2026 | The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted fo... |
| CVE-2026-80437 | MEDIUM | 4.8 | 0.2% | Sep 6, 2026 | The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from b... |
| CVE-2026-19862 | MEDIUM | 4.8 | 0.2% | Sep 6, 2026 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources... |
| CVE-2026-19859 | MEDIUM | 6.5 | 0.2% | Sep 6, 2026 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message ... |
| CVE-2026-86183 | MEDIUM | 5.3 | 0.3% | Sep 6, 2026 | A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmF... |
| CVE-2026-86182 | MEDIUM | 4.3 | 0.2% | Sep 6, 2026 | A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dm... |
| CVE-2026-86179 | MEDIUM | 5.3 | 0.3% | Sep 6, 2026 | A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Exp... |
| CVE-2026-86172 | MEDIUM | 6.3 | 0.2% | Sep 6, 2026 | A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customer... |
| CVE-2026-86171 | MEDIUM | 6.3 | 0.2% | Sep 6, 2026 | A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /mo... |
| CVE-2026-85038 | MEDIUM | 5.3 | 0.2% | Sep 6, 2026 | The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin ... |
| CVE-2026-84028 | MEDIUM | 6.8 | 0.2% | Sep 6, 2026 | The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting... |
| CVE-2026-75793 | MEDIUM | 6.5 | 0.2% | Sep 6, 2026 | The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now