2026 CVE Vulnerabilities
67,214 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-96456 | MEDIUM | 6.3 | — | Sep 23, 2026 | The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects ... |
| CVE-2026-96455 | HIGH | 8.8 | — | Sep 23, 2026 | The Reachy Mini daemon exposes an HTTP API for managing the robot. Its app installation endpoint, POST /apps/install in ... |
| CVE-2026-96442 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends oth... |
| CVE-2026-90950 | MEDIUM | 5.3 | — | Sep 23, 2026 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handle... |
| CVE-2026-87978 | MEDIUM | 5.3 | — | Sep 23, 2026 | The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its pay... |
| CVE-2026-87848 | LOW | 3.7 | — | Sep 23, 2026 | The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its A... |
| CVE-2026-87071 | MEDIUM | 5.3 | — | Sep 23, 2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply... |
| CVE-2026-87070 | MEDIUM | 5.3 | — | Sep 23, 2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before pr... |
| CVE-2026-86612 | MEDIUM | 5.6 | — | Sep 23, 2026 | The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table ro... |
| CVE-2026-86604 | MEDIUM | 4.8 | — | Sep 23, 2026 | The GTranslate WordPress plugin before 5.0.1 does not remove shortcodes from the content of outgoing emails before expan... |
| CVE-2026-86601 | MEDIUM | 6.5 | — | Sep 23, 2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it w... |
| CVE-2026-5696 | MEDIUM | 5.9 | 0.3% | Sep 23, 2026 | Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/setti... |
| CVE-2026-5695 | HIGH | 8.4 | 0.3% | Sep 23, 2026 | Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users ... |
| CVE-2026-96454 | HIGH | 8.2 | 0.5% | Sep 23, 2026 | Pake turns a website into a desktop application built on Tauri. Every application it generates inherits two settings fro... |
| CVE-2026-96443 | MEDIUM | 6.5 | 0.3% | Sep 23, 2026 | Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution... |
| CVE-2026-95627 | HIGH | 7.7 | 0.3% | Sep 23, 2026 | When a Tauri application uses the dialog plugin's file or folder picker, an attacker with JavaScript execution (XSS) can... |
| CVE-2026-95626 | HIGH | 8.3 | 0.5% | Sep 23, 2026 | Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero prot... |
| CVE-2026-94251 | MEDIUM | 6.5 | 0.2% | Sep 23, 2026 | A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resou... |
| CVE-2026-94243 | HIGH | 7.3 | 0.1% | Sep 23, 2026 | A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue af... |
| CVE-2026-92001 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. ... |
| CVE-2026-91999 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. ... |
| CVE-2026-91928 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. ... |
| CVE-2026-91852 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. ... |
| CVE-2026-79616 | LOW | 0.6 | 0.1% | Sep 23, 2026 | Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path. |
| CVE-2026-73192 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when usin... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now