2026 CVE Vulnerabilities
65,007 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-78593 | MEDIUM | 4.3 | 0.2% | Sep 3, 2026 | An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kiban... |
| CVE-2026-49455 | MEDIUM | 6.5 | 0.1% | Sep 3, 2026 | Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes server actions... |
| CVE-2026-84968 | MEDIUM | 5.3 | 0.2% | Sep 3, 2026 | An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who su... |
| CVE-2026-82024 | MEDIUM | 5.4 | 0.1% | Sep 3, 2026 | LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated ... |
| CVE-2026-82023 | MEDIUM | 4.3 | 0.2% | Sep 3, 2026 | LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenti... |
| CVE-2026-85309 | MEDIUM | 5.3 | 0.2% | Sep 3, 2026 | Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Acc... |
| CVE-2026-85308 | MEDIUM | 5.3 | 0.2% | Sep 3, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrect... |
| CVE-2026-85307 | MEDIUM | 5.3 | — | Sep 3, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded ... |
| CVE-2026-85306 | MEDIUM | 6.5 | — | Sep 3, 2026 | Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting I... |
| CVE-2026-85305 | MEDIUM | 5.4 | 0.1% | Sep 3, 2026 | Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEO... |
| CVE-2026-85304 | MEDIUM | 5.3 | — | Sep 3, 2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templa... |
| CVE-2026-85303 | MEDIUM | 6.5 | — | Sep 3, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Bo... |
| CVE-2026-85302 | MEDIUM | 6.5 | 0.1% | Sep 3, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Th... |
| CVE-2026-85242 | MEDIUM | 6.9 | 0.3% | Sep 3, 2026 | PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. Wh... |
| CVE-2026-85186 | MEDIUM | 6.3 | — | Sep 3, 2026 | A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is th... |
| CVE-2026-84849 | MEDIUM | 6.5 | — | Sep 3, 2026 | Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions. |
| CVE-2026-84774 | MEDIUM | 6.1 | 0.1% | Sep 3, 2026 | Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions. |
| CVE-2026-84769 | MEDIUM | 6.5 | 0.2% | Sep 3, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions. |
| CVE-2026-84767 | MEDIUM | 5.3 | — | Sep 3, 2026 | Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. |
| CVE-2026-84766 | MEDIUM | 5.9 | 0.2% | Sep 3, 2026 | Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. |
| CVE-2026-84762 | MEDIUM | 5.3 | — | Sep 3, 2026 | Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions. |
| CVE-2026-84758 | MEDIUM | 6.5 | 0.2% | Sep 3, 2026 | Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. |
| CVE-2026-84755 | MEDIUM | 6.5 | — | Sep 3, 2026 | Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions. |
| CVE-2026-84754 | MEDIUM | 6.5 | — | Sep 3, 2026 | Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions. |
| CVE-2026-84215 | MEDIUM | 6.5 | — | Sep 3, 2026 | Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now