2026 CVE Vulnerabilities
67,276 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82560 | HIGH | 7.5 | 0.6% | Sep 19, 2026 | Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting d... |
| CVE-2026-94001 | MEDIUM | 6.5 | 0.3% | Sep 19, 2026 | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint... |
| CVE-2026-94000 | MEDIUM | 6.6 | 0.2% | Sep 19, 2026 | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue oc... |
| CVE-2026-93999 | MEDIUM | 4.2 | 0.1% | Sep 19, 2026 | A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution... |
| CVE-2026-93987 | LOW | 3.4 | 0.1% | Sep 19, 2026 | rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin.... |
| CVE-2026-93986 | LOW | 3.1 | 0.2% | Sep 19, 2026 | rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allow... |
| CVE-2026-93985 | CRITICAL | 9.9 | 0.7% | Sep 19, 2026 | OpenPanel js-runtime through 2.3.0 contains a sandbox escape vulnerability in the JavaScript webhook template validator ... |
| CVE-2026-93984 | MEDIUM | 5.3 | 0.4% | Sep 19, 2026 | OpenPanel tracking API through 2.3.0 fails to verify client secret cryptographic hash before authorizing revenue events ... |
| CVE-2026-93983 | MEDIUM | 5 | 0.3% | Sep 19, 2026 | OpenPanel through 2.3.0 fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject ... |
| CVE-2026-93982 | LOW | 3.3 | 0.2% | Sep 19, 2026 | OpenPanel through 2.3.0 writes Model Context Protocol authentication tokens from URL query parameters to plaintext appli... |
| CVE-2026-93981 | MEDIUM | 4.7 | 0.1% | Sep 19, 2026 | hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a stri... |
| CVE-2026-78030 | CRITICAL | 9.8 | 0.7% | Sep 19, 2026 | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.... |
| CVE-2026-9858 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and ... |
| CVE-2026-9766 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin... |
| CVE-2026-9613 | MEDIUM | 4.3 | 0.3% | Sep 19, 2026 | The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all version... |
| CVE-2026-9289 | MEDIUM | 5.3 | 0.4% | Sep 19, 2026 | The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi... |
| CVE-2026-93742 | CRITICAL | 9.9 | 1.9% | Sep 19, 2026 | A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of ... |
| CVE-2026-8354 | MEDIUM | 6.4 | 0.2% | Sep 19, 2026 | The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' paramete... |
| CVE-2026-76579 | MEDIUM | 4.7 | 0.2% | Sep 19, 2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all ... |
| CVE-2026-5410 | MEDIUM | 6.4 | 0.2% | Sep 19, 2026 | The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions ... |
| CVE-2026-1256 | MEDIUM | 6.4 | 0.2% | Sep 19, 2026 | The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple A... |
| CVE-2026-1255 | HIGH | 7.5 | 0.3% | Sep 19, 2026 | The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including... |
| CVE-2026-18346 | MEDIUM | 5.3 | 0.3% | Sep 19, 2026 | The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This ... |
| CVE-2026-9855 | MEDIUM | 6.5 | 0.3% | Sep 19, 2026 | The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all... |
| CVE-2026-9832 | MEDIUM | 5.3 | 0.2% | Sep 19, 2026 | The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptograph... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now