2026 CVE Vulnerabilities
64,755 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-78313 | MEDIUM | 6.5 | 0.5% | Sep 24, 2026 | Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-78310 | MEDIUM | 4.3 | 0.2% | Sep 24, 2026 | Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-97181 | MEDIUM | 5.3 | 0.3% | Sep 24, 2026 | GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can direct... |
| CVE-2026-87739 | MEDIUM | 6.9 | 0.4% | Sep 24, 2026 | An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report ... |
| CVE-2026-81645 | MEDIUM | 5.9 | 0.1% | Sep 24, 2026 | Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availa... |
| CVE-2026-97177 | MEDIUM | 6.6 | 0.2% | Sep 24, 2026 | A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are en... |
| CVE-2026-97176 | MEDIUM | 4.2 | 0.2% | Sep 24, 2026 | A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management sol... |
| CVE-2026-93662 | MEDIUM | 4.3 | 0.1% | Sep 24, 2026 | The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search wh... |
| CVE-2026-89005 | MEDIUM | 6.8 | 0.2% | Sep 24, 2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configura... |
| CVE-2026-89002 | MEDIUM | 6.8 | 0.2% | Sep 24, 2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a u... |
| CVE-2026-88847 | MEDIUM | 4.3 | 0.1% | Sep 24, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course... |
| CVE-2026-88846 | MEDIUM | 5.3 | 0.1% | Sep 24, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled... |
| CVE-2026-88845 | MEDIUM | 4.3 | 0.1% | Sep 24, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on ... |
| CVE-2026-82850 | MEDIUM | 4.3 | 0.1% | Sep 24, 2026 | The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticate... |
| CVE-2026-82849 | MEDIUM | 4.3 | 0.1% | Sep 24, 2026 | The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progre... |
| CVE-2026-82195 | MEDIUM | 6.5 | 0.1% | Sep 24, 2026 | The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret... |
| CVE-2026-80338 | MEDIUM | 6.8 | 0.1% | Sep 24, 2026 | The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users... |
| CVE-2026-74991 | MEDIUM | 6.8 | 0.1% | Sep 24, 2026 | The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form su... |
| CVE-2026-97155 | MEDIUM | 6.5 | 0.1% | Sep 24, 2026 | Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension v... |
| CVE-2026-96892 | MEDIUM | 4.3 | 0.3% | Sep 24, 2026 | A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component gofor... |
| CVE-2026-97149 | MEDIUM | 5.3 | 0.2% | Sep 24, 2026 | In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempU... |
| CVE-2026-96884 | MEDIUM | 6.3 | 0.3% | Sep 24, 2026 | A security flaw has been discovered in MantisZip up to 0.4.5. Affected by this issue is the function Path.Combine of the... |
| CVE-2026-96882 | MEDIUM | 5.3 | 0.3% | Sep 24, 2026 | A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the functio... |
| CVE-2026-96881 | MEDIUM | 5.3 | 0.3% | Sep 24, 2026 | A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks of the file... |
| CVE-2026-97056 | MEDIUM | 6.8 | 0.4% | Sep 24, 2026 | SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (wh... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now