2026 CVE Vulnerabilities
65,328 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93000 | MEDIUM | 6.8 | — | Sep 28, 2026 | The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its ... |
| CVE-2026-92996 | MEDIUM | 5.3 | — | Sep 28, 2026 | The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actu... |
| CVE-2026-89411 | MEDIUM | 5.3 | — | Sep 28, 2026 | The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the ... |
| CVE-2026-89303 | MEDIUM | 6.4 | — | Sep 28, 2026 | The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in... |
| CVE-2026-89300 | MEDIUM | 5.3 | — | Sep 28, 2026 | The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowi... |
| CVE-2026-88828 | MEDIUM | 5.4 | — | Sep 28, 2026 | The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every a... |
| CVE-2026-86838 | MEDIUM | 5.3 | — | Sep 28, 2026 | The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before c... |
| CVE-2026-84744 | MEDIUM | 6.5 | — | Sep 28, 2026 | The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values... |
| CVE-2026-101009 | HIGH | 8.4 | — | Sep 28, 2026 | A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._un... |
| CVE-2026-101008 | CRITICAL | 9.1 | — | Sep 28, 2026 | A vulnerability was found in aaPanel BaoTa up to 11.8.0. Impacted is the function merge_split_file of the file /www/serv... |
| CVE-2026-101007 | HIGH | 8.4 | — | Sep 28, 2026 | A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputSql of the file class... |
| CVE-2026-101006 | MEDIUM | 4.3 | — | Sep 28, 2026 | A flaw has been found in Frappe HR up to 16.15.0. This vulnerability affects the function get_expense_claims/get_shift_r... |
| CVE-2026-101005 | HIGH | 7.3 | — | Sep 28, 2026 | A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file... |
| CVE-2026-100751 | HIGH | 7.5 | — | Sep 28, 2026 | Joomla Extension - regularlabs.com - Privileged stored XSS via data-rlta-url attributes in Tabs & Accordions (Pro) 2.3.0... |
| CVE-2026-100750 | HIGH | 8.5 | — | Sep 28, 2026 | Joomla Extension - regularlabs.com - LFI / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla - Modules Anywhere Pro lets... |
| CVE-2026-101004 | MEDIUM | 5.3 | — | Sep 28, 2026 | A security vulnerability has been detected in notionnext-org NotionNext up to 4.10.10. Affected by this issue is the fun... |
| CVE-2026-101003 | MEDIUM | 5.3 | — | Sep 28, 2026 | A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the ... |
| CVE-2026-101002 | CRITICAL | 9.9 | — | Sep 28, 2026 | A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. Affected is the function system of the file /... |
| CVE-2026-87723 | MEDIUM | 5.4 | 0.1% | Sep 28, 2026 | In Google fuse-archive versions prior to 1.24, an attacker who can prepend a directory to PATH or write a malicious bina... |
| CVE-2026-101001 | CRITICAL | 10 | — | Sep 28, 2026 | A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This impacts the function eval of the file /www/cg... |
| CVE-2026-101000 | CRITICAL | 10 | — | Sep 28, 2026 | A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /u... |
| CVE-2026-100909 | HIGH | 7.3 | — | Sep 28, 2026 | A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathFor... |
| CVE-2026-100908 | HIGH | 7.5 | — | Sep 28, 2026 | A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the component p2pcam HTTP Par... |
| CVE-2026-100907 | MEDIUM | 5.3 | — | Sep 28, 2026 | A flaw has been found in Eyeplus 57.0.0.0308. The impacted element is an unknown function of the file /snapshot of the c... |
| CVE-2026-100906 | MEDIUM | 5.3 | — | Sep 28, 2026 | A vulnerability was detected in Eyeplus 57.0.0.0308. The affected element is the function GetUsers of the file /onvif/De... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now