2026 CVE Vulnerabilities
67,237 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25265 | HIGH | 8.8 | 0.1% | Sep 22, 2026 | Privilege escalation due to weak configuration while temporary file handling. |
| CVE-2026-25264 | HIGH | 8.8 | 0.1% | Sep 22, 2026 | Privilege escalation due to weak configuration during package extraction process. |
| CVE-2026-25262 | MEDIUM | 6.9 | — | Sep 22, 2026 | Memory corruption while processing a crafted ELF file in the Primary Bootloader. |
| CVE-2026-25255 | HIGH | 8.8 | — | Sep 22, 2026 | Exposed dangerous function lead to privilege escalation via gRPC server. |
| CVE-2026-25254 | CRITICAL | 9.8 | 0.5% | Sep 22, 2026 | Improper authorization leads to Remote Code Execution via SocketIO interface. |
| CVE-2026-9231 | HIGH | 7.5 | 0.6% | Sep 22, 2026 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inc... |
| CVE-2026-95511 | — | — | 0.1% | Sep 22, 2026 | Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in Sys... |
| CVE-2026-95508 | HIGH | 7.4 | 0.4% | Sep 22, 2026 | A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured... |
| CVE-2026-93928 | HIGH | 7.3 | 0.3% | Sep 22, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCo... |
| CVE-2026-93556 | CRITICAL | 9.3 | 0.3% | Sep 22, 2026 | The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose passwor... |
| CVE-2026-89422 | CRITICAL | 9.3 | 0.4% | Sep 22, 2026 | Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client c... |
| CVE-2026-68956 | HIGH | 7.1 | 0.7% | Sep 22, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote atta... |
| CVE-2026-65634 | HIGH | 8.2 | 0.4% | Sep 22, 2026 | Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated atta... |
| CVE-2026-15095 | MEDIUM | 4.9 | 1.2% | Sep 22, 2026 | The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vu... |
| CVE-2026-9004 | MEDIUM | 4.3 | 0.2% | Sep 22, 2026 | The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in ... |
| CVE-2026-95503 | MEDIUM | 6.8 | 0.1% | Sep 22, 2026 | A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution... |
| CVE-2026-93952 | CRITICAL | 10 | 0.7% | Sep 22, 2026 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privile... |
| CVE-2026-93836 | HIGH | 7.2 | 0.2% | Sep 22, 2026 | The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' ... |
| CVE-2026-93778 | HIGH | 7.2 | 0.2% | Sep 22, 2026 | The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (import... |
| CVE-2026-92969 | HIGH | 8.1 | 0.7% | Sep 22, 2026 | The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in a... |
| CVE-2026-92235 | HIGH | 8.1 | 0.4% | Sep 22, 2026 | The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an... |
| CVE-2026-91092 | MEDIUM | 4.3 | 0.2% | Sep 22, 2026 | The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5.... |
| CVE-2026-87082 | HIGH | 7.5 | 0.2% | Sep 22, 2026 | Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in... |
| CVE-2026-87081 | HIGH | 7.5 | 0.2% | Sep 22, 2026 | Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label... |
| CVE-2026-87080 | CRITICAL | 9.1 | 0.1% | Sep 22, 2026 | Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now