2026 CVE Vulnerabilities
67,183 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-74991 | MEDIUM | 6.8 | 0.1% | Sep 24, 2026 | The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form su... |
| CVE-2026-14780 | HIGH | 7.5 | 0.3% | Sep 24, 2026 | A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization ... |
| CVE-2026-97155 | MEDIUM | 6.5 | 0.1% | Sep 24, 2026 | Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension v... |
| CVE-2026-97152 | HIGH | 8.6 | 0.3% | Sep 24, 2026 | Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport... |
| CVE-2026-97151 | HIGH | 8.4 | 0.4% | Sep 24, 2026 | mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a documen... |
| CVE-2026-96898 | HIGH | 7.3 | 0.4% | Sep 24, 2026 | A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality... |
| CVE-2026-96892 | MEDIUM | 4.3 | 0.3% | Sep 24, 2026 | A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component gofor... |
| CVE-2026-97149 | MEDIUM | 5.3 | 0.2% | Sep 24, 2026 | In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempU... |
| CVE-2026-96891 | CRITICAL | 9.8 | 0.7% | Sep 24, 2026 | A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.... |
| CVE-2026-96884 | MEDIUM | 6.3 | 0.3% | Sep 24, 2026 | A security flaw has been discovered in MantisZip up to 0.4.5. Affected by this issue is the function Path.Combine of the... |
| CVE-2026-96882 | MEDIUM | 5.3 | — | Sep 24, 2026 | A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the functio... |
| CVE-2026-96881 | MEDIUM | 5.3 | 0.3% | Sep 24, 2026 | A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks of the file... |
| CVE-2026-97056 | MEDIUM | 6.8 | 0.4% | Sep 24, 2026 | SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (wh... |
| CVE-2026-97055 | HIGH | 8.1 | 0.4% | Sep 24, 2026 | SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOK... |
| CVE-2026-96880 | MEDIUM | 5.3 | 0.3% | Sep 24, 2026 | A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/... |
| CVE-2026-96810 | LOW | 3.5 | 0.2% | Sep 24, 2026 | A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This issue affec... |
| CVE-2026-96803 | HIGH | 7.3 | 0.3% | Sep 24, 2026 | A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBac... |
| CVE-2026-96777 | MEDIUM | 6.3 | — | Sep 24, 2026 | A vulnerability was determined in Forma LMS up to 4.1.43. This impacts the function UserselectorAdmController::getDataTa... |
| CVE-2026-18467 | CRITICAL | 9.8 | 0.4% | Sep 24, 2026 | The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions... |
| CVE-2026-96774 | MEDIUM | 5.3 | 0.3% | Sep 24, 2026 | A vulnerability was found in SPON Communications IP Network Audio Device XC-9603 1.2.3_20181106 Build 107. This affects ... |
| CVE-2026-96773 | MEDIUM | 4.3 | 0.3% | Sep 24, 2026 | A weakness has been identified in Intelliants Subrion CMS up to 4.2.1. This vulnerability affects the function iaUsers::... |
| CVE-2026-96772 | MEDIUM | 5.3 | 0.3% | Sep 24, 2026 | A security flaw has been discovered in Intelliants Subrion CMS up to 4.2.1. This affects an unknown part of the file /ac... |
| CVE-2026-96764 | MEDIUM | 4.3 | 0.3% | Sep 24, 2026 | A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::G... |
| CVE-2026-96763 | MEDIUM | 5.4 | — | Sep 24, 2026 | A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the ... |
| CVE-2026-96762 | HIGH | 7.3 | 0.3% | Sep 24, 2026 | A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegmen... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now