2026 CVE Vulnerabilities
67,167 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15731 | MEDIUM | 6.4 | 0.3% | Sep 24, 2026 | The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2026-12227 | CRITICAL | 9.8 | 0.8% | Sep 24, 2026 | The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an... |
| CVE-2026-97185 | HIGH | 7.8 | 0.1% | Sep 24, 2026 | A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly ... |
| CVE-2026-85682 | HIGH | 8.8 | 0.1% | Sep 24, 2026 | The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10.... |
| CVE-2026-78313 | MEDIUM | 6.5 | 0.5% | Sep 24, 2026 | Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-78312 | CRITICAL | 9.1 | 0.3% | Sep 24, 2026 | Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-78311 | HIGH | 8.8 | 0.2% | Sep 24, 2026 | SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-78310 | MEDIUM | 4.3 | 0.2% | Sep 24, 2026 | Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-78309 | HIGH | 8.8 | 0.2% | Sep 24, 2026 | SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-78308 | CRITICAL | 9.8 | 0.3% | Sep 24, 2026 | Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before... |
| CVE-2026-77193 | HIGH | 7.5 | 0.4% | Sep 24, 2026 | The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and ... |
| CVE-2026-97181 | MEDIUM | 5.3 | 0.3% | Sep 24, 2026 | GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can direct... |
| CVE-2026-87739 | MEDIUM | 6.9 | 0.4% | Sep 24, 2026 | An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report ... |
| CVE-2026-82077 | HIGH | 7.3 | 0.7% | Sep 24, 2026 | An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax compone... |
| CVE-2026-81645 | MEDIUM | 5.9 | 0.1% | Sep 24, 2026 | Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availa... |
| CVE-2026-11744 | LOW | 3.8 | 0.2% | Sep 24, 2026 | An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fa... |
| CVE-2026-97177 | MEDIUM | 6.6 | 0.2% | Sep 24, 2026 | A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are en... |
| CVE-2026-97176 | MEDIUM | 4.2 | 0.2% | Sep 24, 2026 | A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management sol... |
| CVE-2026-97168 | — | — | — | Sep 24, 2026 | Rejected reason: it is a suggestion |
| CVE-2026-93662 | MEDIUM | 4.3 | 0.1% | Sep 24, 2026 | The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search wh... |
| CVE-2026-93661 | LOW | 2.7 | 0.1% | Sep 24, 2026 | The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers o... |
| CVE-2026-89005 | MEDIUM | 6.8 | 0.2% | Sep 24, 2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configura... |
| CVE-2026-89004 | LOW | 2.7 | 0.1% | Sep 24, 2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returnin... |
| CVE-2026-89002 | MEDIUM | 6.8 | 0.2% | Sep 24, 2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a u... |
| CVE-2026-88847 | MEDIUM | 4.3 | 0.1% | Sep 24, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now