2026 CVE Vulnerabilities
64,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-80190 | MEDIUM | 6.1 | 0.2% | Sep 4, 2026 | Apache Allura: stored XSS via SVN code repositories. Git repositories are not known to be affected. The vulnerability ... |
| CVE-2026-6217 | MEDIUM | 6.3 | 0.1% | Sep 4, 2026 | Use of a One-Way hash without a salt vulnerability in Pik Online Software Solutions Inc. Pik Online Portal allows Crypta... |
| CVE-2026-84146 | MEDIUM | 5.3 | 0.2% | Sep 4, 2026 | The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-statu... |
| CVE-2026-82194 | MEDIUM | 5.5 | 0.2% | Sep 4, 2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before ... |
| CVE-2026-82193 | MEDIUM | 5.5 | 0.3% | Sep 4, 2026 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name be... |
| CVE-2026-82186 | MEDIUM | 4.1 | 0.2% | Sep 4, 2026 | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it... |
| CVE-2026-81347 | MEDIUM | 5.9 | 0.2% | Sep 4, 2026 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable director... |
| CVE-2026-80438 | MEDIUM | 5.9 | 0.1% | Sep 4, 2026 | The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninj... |
| CVE-2026-80180 | MEDIUM | 6.1 | 0.2% | Sep 4, 2026 | Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. U... |
| CVE-2026-79632 | MEDIUM | 5.3 | 0.2% | Sep 4, 2026 | The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in sub... |
| CVE-2026-79631 | MEDIUM | 5.3 | 0.2% | Sep 4, 2026 | The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable locat... |
| CVE-2026-79630 | MEDIUM | 5.3 | 0.2% | Sep 4, 2026 | The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump i... |
| CVE-2026-74853 | MEDIUM | 6.8 | 0.2% | Sep 4, 2026 | The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing ... |
| CVE-2026-71216 | MEDIUM | 5.3 | 0.1% | Sep 4, 2026 | PagerDuty alarm hook transmits the integration routing key over cleartext HTTP. PagerDuty serves this endpoint over H... |
| CVE-2026-17517 | MEDIUM | 5.3 | 0.2% | Sep 4, 2026 | The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read ... |
| CVE-2026-85409 | MEDIUM | 6.3 | 0.3% | Sep 4, 2026 | A vulnerability was identified in Eleveo Quality Management 9.7.0. The affected element is the function QuestionnaireSer... |
| CVE-2026-85408 | MEDIUM | 4.3 | 0.2% | Sep 4, 2026 | A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-... |
| CVE-2026-85407 | MEDIUM | 4.3 | 0.3% | Sep 4, 2026 | A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /en... |
| CVE-2026-85401 | MEDIUM | 6.3 | 0.3% | Sep 4, 2026 | A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functional... |
| CVE-2026-85149 | MEDIUM | 5.3 | 0.2% | Sep 4, 2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote... |
| CVE-2026-85383 | MEDIUM | 6.3 | 0.2% | Sep 4, 2026 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the... |
| CVE-2026-85382 | MEDIUM | 4.3 | 0.3% | Sep 4, 2026 | A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f6138... |
| CVE-2026-85381 | MEDIUM | 5.3 | 0.3% | Sep 4, 2026 | A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a061... |
| CVE-2026-49509 | MEDIUM | 4.4 | 0.1% | Sep 4, 2026 | Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 256... |
| CVE-2026-85456 | MEDIUM | 5.5 | 0.1% | Sep 3, 2026 | MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowin... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now