2026 CVE Vulnerabilities
67,245 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-88788 | MEDIUM | 6.8 | 0.2% | Sep 22, 2026 | The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputti... |
| CVE-2026-85653 | MEDIUM | 6.4 | 0.3% | Sep 22, 2026 | The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'other_attributes' Bl... |
| CVE-2026-12470 | HIGH | 7.2 | 0.3% | Sep 22, 2026 | The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modificatio... |
| CVE-2026-19658 | CRITICAL | 9.8 | 0.4% | Sep 22, 2026 | The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1... |
| CVE-2026-13355 | CRITICAL | 9.8 | 0.3% | Sep 22, 2026 | The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and incl... |
| CVE-2026-94493 | CRITICAL | 10 | 1.3% | Sep 22, 2026 | A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the... |
| CVE-2026-94492 | MEDIUM | 6.3 | 0.2% | Sep 22, 2026 | A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u... |
| CVE-2026-94491 | HIGH | 7.3 | 0.3% | Sep 22, 2026 | A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. E... |
| CVE-2026-93712 | HIGH | 7.5 | 0.2% | Sep 22, 2026 | Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the ... |
| CVE-2026-93711 | MEDIUM | 6.5 | 0.2% | Sep 22, 2026 | Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routi... |
| CVE-2026-93710 | HIGH | 7.5 | 0.2% | Sep 22, 2026 | Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler ... |
| CVE-2026-93709 | MEDIUM | 5.3 | 0.2% | Sep 22, 2026 | Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard... |
| CVE-2026-76974 | MEDIUM | 5.3 | 0.2% | Sep 22, 2026 | SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craf... |
| CVE-2026-94490 | MEDIUM | 4.7 | 2.1% | Sep 22, 2026 | A security flaw has been discovered in OctoPrint 1.0.0. Affected by this issue is the function executeSystemCommand of t... |
| CVE-2026-94489 | MEDIUM | 4.3 | 0.4% | Sep 22, 2026 | A vulnerability was identified in OctoPrint 1.0.0. Affected by this vulnerability is the function _validate of the file ... |
| CVE-2026-94426 | LOW | 3.5 | 0.3% | Sep 21, 2026 | A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /... |
| CVE-2026-94425 | HIGH | 8.8 | 0.1% | Sep 21, 2026 | A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_1400... |
| CVE-2026-94627 | HIGH | 7.5 | — | Sep 21, 2026 | vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child reque... |
| CVE-2026-94626 | HIGH | 7.5 | — | Sep 21, 2026 | vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoi... |
| CVE-2026-94625 | MEDIUM | 5.3 | — | Sep 21, 2026 | vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests cr... |
| CVE-2026-94624 | HIGH | 7.5 | — | Sep 21, 2026 | vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configur... |
| CVE-2026-94623 | HIGH | 7.5 | — | Sep 21, 2026 | vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation tha... |
| CVE-2026-94622 | HIGH | 7.5 | — | Sep 21, 2026 | vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for pre... |
| CVE-2026-94540 | HIGH | 7.7 | 0.2% | Sep 21, 2026 | DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, r... |
| CVE-2026-94536 | MEDIUM | 4.3 | 0.2% | Sep 21, 2026 | lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now