2026 CVE Vulnerabilities
67,214 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84026 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restric... |
| CVE-2026-83555 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token ... |
| CVE-2026-82843 | CRITICAL | 9 | 0.2% | Sep 23, 2026 | The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity ass... |
| CVE-2026-81339 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when ... |
| CVE-2026-81338 | MEDIUM | 4.6 | 0.1% | Sep 23, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in use... |
| CVE-2026-80342 | MEDIUM | 6.5 | 0.2% | Sep 23, 2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied i... |
| CVE-2026-77766 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope o... |
| CVE-2026-77765 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the... |
| CVE-2026-75799 | CRITICAL | 9 | 0.2% | Sep 23, 2026 | The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly... |
| CVE-2026-19438 | HIGH | 7.5 | 0.4% | Sep 23, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Mint Workbench I. T... |
| CVE-2026-18365 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, al... |
| CVE-2026-18364 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on several of its AJAX actions... |
| CVE-2026-16264 | MEDIUM | 6.5 | 0.2% | Sep 23, 2026 | The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management ... |
| CVE-2026-14321 | HIGH | 8.2 | 0.2% | Sep 23, 2026 | The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limit... |
| CVE-2026-96258 | MEDIUM | 4.3 | 0.3% | Sep 23, 2026 | A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. This affects an unkno... |
| CVE-2026-96257 | CRITICAL | 10 | 1.0% | Sep 23, 2026 | A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of... |
| CVE-2026-95958 | LOW | 3.3 | 0.2% | Sep 23, 2026 | A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of th... |
| CVE-2026-95957 | MEDIUM | 4.3 | 0.5% | Sep 23, 2026 | A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the fun... |
| CVE-2026-95930 | MEDIUM | 6.3 | 0.4% | Sep 23, 2026 | A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the fu... |
| CVE-2026-95929 | MEDIUM | 6.3 | 0.2% | Sep 23, 2026 | A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/... |
| CVE-2026-91777 | HIGH | 7.5 | 0.4% | Sep 23, 2026 | Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of th... |
| CVE-2026-91776 | HIGH | 7.5 | 0.4% | Sep 23, 2026 | TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, a... |
| CVE-2026-89425 | HIGH | 7.5 | 0.5% | Sep 23, 2026 | UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error me... |
| CVE-2026-95928 | MEDIUM | 5.5 | 0.3% | Sep 23, 2026 | A security flaw has been discovered in recommenders-team recommenders up to 1.2.1. This impacts the function pickle.load... |
| CVE-2026-95927 | HIGH | 7.3 | 0.4% | Sep 23, 2026 | A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now