2026 CVE Vulnerabilities
67,214 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-91799 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of JavaScript array objects. A specially cra... |
| CVE-2026-91798 | HIGH | 8.8 | 0.1% | Sep 23, 2026 | A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure per... |
| CVE-2026-91797 | HIGH | 7.8 | 0.3% | Sep 23, 2026 | Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malici... |
| CVE-2026-91796 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows special... |
| CVE-2026-91795 | HIGH | 7.8 | 0.1% | Sep 23, 2026 | Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted P... |
| CVE-2026-91794 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient ... |
| CVE-2026-91793 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attribut... |
| CVE-2026-91792 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations throug... |
| CVE-2026-91791 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition invo... |
| CVE-2026-91790 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional conte... |
| CVE-2026-91789 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and relate... |
| CVE-2026-91788 | MEDIUM | 4.7 | 0.1% | Sep 23, 2026 | When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks r... |
| CVE-2026-50228 | MEDIUM | 6.1 | 0.1% | Sep 23, 2026 | An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (ver... |
| CVE-2026-50227 | MEDIUM | 6.1 | 0.3% | Sep 23, 2026 | An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSens... |
| CVE-2026-82331 | CRITICAL | 9.8 | 0.2% | Sep 23, 2026 | Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildS... |
| CVE-2026-6831 | MEDIUM | 6.5 | 0.4% | Sep 23, 2026 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and in... |
| CVE-2026-5924 | MEDIUM | 6.4 | 0.3% | Sep 23, 2026 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps bloc... |
| CVE-2026-93528 | LOW | 3.7 | 0.2% | Sep 23, 2026 | The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an ... |
| CVE-2026-93511 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment... |
| CVE-2026-93510 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or res... |
| CVE-2026-93508 | HIGH | 8.1 | 0.2% | Sep 23, 2026 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX acti... |
| CVE-2026-93507 | LOW | 3.3 | 0.2% | Sep 23, 2026 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post... |
| CVE-2026-91077 | LOW | 2.7 | 0.2% | Sep 23, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to ev... |
| CVE-2026-91073 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputti... |
| CVE-2026-91025 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager W... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now