2026 CVE Vulnerabilities
67,199 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-96545 | MEDIUM | 4.4 | 0.2% | Sep 23, 2026 | An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that ca... |
| CVE-2026-96541 | HIGH | 7.5 | 0.8% | Sep 23, 2026 | A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections ... |
| CVE-2026-95604 | HIGH | 7.5 | — | Sep 23, 2026 | Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions. |
| CVE-2026-95603 | HIGH | 7.2 | — | Sep 23, 2026 | Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions. |
| CVE-2026-95602 | MEDIUM | 6.5 | — | Sep 23, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploitin... |
| CVE-2026-95601 | CRITICAL | 9.3 | — | Sep 23, 2026 | Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions. |
| CVE-2026-95600 | MEDIUM | 5.3 | — | Sep 23, 2026 | Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions. |
| CVE-2026-95593 | HIGH | 7.6 | — | Sep 23, 2026 | Editor SQL Injection in Ultimeter <= 3.0.8 versions. |
| CVE-2026-95592 | MEDIUM | 5.3 | — | Sep 23, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions. |
| CVE-2026-95590 | HIGH | 7.1 | — | Sep 23, 2026 | Subscriber SQL Injection in Tainacan <= 1.2.0 versions. |
| CVE-2026-95586 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions. |
| CVE-2026-95530 | MEDIUM | 6.5 | — | Sep 23, 2026 | Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions. |
| CVE-2026-95529 | HIGH | 7.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions. |
| CVE-2026-95528 | HIGH | 7.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions. |
| CVE-2026-95527 | MEDIUM | 6.5 | — | Sep 23, 2026 | Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions. |
| CVE-2026-95525 | MEDIUM | 6.5 | — | Sep 23, 2026 | Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions. |
| CVE-2026-95524 | MEDIUM | 5.3 | — | Sep 23, 2026 | Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. |
| CVE-2026-95523 | MEDIUM | 6.5 | — | Sep 23, 2026 | Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. |
| CVE-2026-95522 | HIGH | 7.6 | — | Sep 23, 2026 | Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. |
| CVE-2026-95515 | HIGH | 7.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. |
| CVE-2026-95514 | MEDIUM | 5.3 | — | Sep 23, 2026 | Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions. |
| CVE-2026-95513 | HIGH | 7.5 | — | Sep 23, 2026 | Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions. |
| CVE-2026-94684 | — | — | 0.2% | Sep 23, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. False positive detection. |
| CVE-2026-94682 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions. |
| CVE-2026-94680 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now