2026 CVE Vulnerabilities
64,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85586 | MEDIUM | 6.9 | 0.4% | Sep 4, 2026 | phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store parameter is set to 'now' in question submission ... |
| CVE-2026-85583 | MEDIUM | 6.5 | 0.5% | Sep 4, 2026 | SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that fo... |
| CVE-2026-85582 | MEDIUM | 6.5 | 0.4% | Sep 4, 2026 | SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth hand... |
| CVE-2026-85580 | MEDIUM | 6.5 | 0.5% | Sep 4, 2026 | SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-se... |
| CVE-2026-85579 | MEDIUM | 4.3 | 0.2% | Sep 4, 2026 | SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-acces... |
| CVE-2026-85578 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows reader... |
| CVE-2026-85577 | MEDIUM | 5.4 | 0.3% | Sep 4, 2026 | AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows una... |
| CVE-2026-19043 | MEDIUM | 4.3 | 0.2% | Sep 4, 2026 | Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly ... |
| CVE-2026-18957 | MEDIUM | 5.4 | 0.2% | Sep 4, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software I... |
| CVE-2026-85534 | MEDIUM | 5.9 | 0.3% | Sep 4, 2026 | A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library ca... |
| CVE-2026-84045 | MEDIUM | 5.3 | 0.2% | Sep 4, 2026 | The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip di... |
| CVE-2026-27347 | MEDIUM | 5.3 | — | Sep 4, 2026 | Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2026-85547 | MEDIUM | 6.2 | 0.3% | Sep 4, 2026 | A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disable... |
| CVE-2026-85541 | MEDIUM | 5.4 | 0.3% | Sep 4, 2026 | DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can... |
| CVE-2026-84044 | MEDIUM | 5.3 | 0.1% | Sep 4, 2026 | The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification ... |
| CVE-2026-84043 | MEDIUM | 5.3 | 0.1% | Sep 4, 2026 | The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of pa... |
| CVE-2026-81666 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check fo... |
| CVE-2026-27086 | MEDIUM | 6.5 | 0.1% | Sep 4, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart al... |
| CVE-2026-13148 | MEDIUM | 6.3 | 0.4% | Sep 4, 2026 | Missing release of memory after effective lifetime vulnerability in Softing smartLink allows resource leak exposure. Th... |
| CVE-2026-85528 | MEDIUM | 5.3 | 0.2% | Sep 4, 2026 | Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4... |
| CVE-2026-85311 | MEDIUM | 5.3 | 0.2% | Sep 4, 2026 | Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-32480 | MEDIUM | 5.3 | 0.2% | Sep 4, 2026 | Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control... |
| CVE-2026-27432 | MEDIUM | 5.4 | 0.2% | Sep 4, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorre... |
| CVE-2026-15937 | MEDIUM | 5.3 | 0.1% | Sep 4, 2026 | Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse e... |
| CVE-2026-85229 | MEDIUM | 6.1 | 0.2% | Sep 4, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vul... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now