2026 CVE Vulnerabilities
67,295 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-87909 | HIGH | 7.5 | 0.5% | Sep 19, 2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_m... |
| CVE-2026-84434 | CRITICAL | 9.8 | 0.7% | Sep 19, 2026 | The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.... |
| CVE-2026-15760 | MEDIUM | 6.5 | 0.2% | Sep 19, 2026 | The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including... |
| CVE-2026-15660 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7. Thi... |
| CVE-2026-13354 | HIGH | 7.2 | 0.2% | Sep 19, 2026 | The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Cont... |
| CVE-2026-12042 | MEDIUM | 4.4 | 0.2% | Sep 19, 2026 | The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v... |
| CVE-2026-77820 | MEDIUM | 6.4 | 0.2% | Sep 19, 2026 | The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all ... |
| CVE-2026-93923 | HIGH | 8.8 | 0.4% | Sep 19, 2026 | SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing st... |
| CVE-2026-93922 | HIGH | 8.8 | 0.5% | Sep 19, 2026 | SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing store... |
| CVE-2026-93921 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only ... |
| CVE-2026-77875 | MEDIUM | 6.8 | 0.2% | Sep 19, 2026 | The application protects access through its calculator-style vault passcode, but the stored data is not bound to that au... |
| CVE-2026-93740 | CRITICAL | 10 | 0.6% | Sep 18, 2026 | A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file... |
| CVE-2026-93739 | CRITICAL | 9.9 | 0.5% | Sep 18, 2026 | A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /bo... |
| CVE-2026-75885 | CRITICAL | 9.3 | 0.7% | Sep 18, 2026 | A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` end... |
| CVE-2026-93894 | LOW | 2.3 | 0.3% | Sep 18, 2026 | In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type ... |
| CVE-2026-93738 | CRITICAL | 9.9 | 0.5% | Sep 18, 2026 | A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boa... |
| CVE-2026-93574 | MEDIUM | 6.5 | 0.5% | Sep 18, 2026 | A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending ... |
| CVE-2026-93562 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote... |
| CVE-2026-88097 | HIGH | 7.8 | 0.3% | Sep 18, 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-85272 | MEDIUM | 4.3 | 0.5% | Sep 18, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawo... |
| CVE-2026-85271 | MEDIUM | 6.1 | 0.4% | Sep 18, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. From Redwood until Ulmo and Verawo... |
| CVE-2026-71855 | HIGH | 7.5 | — | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2026-71418 | HIGH | 7.5 | — | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr... |
| CVE-2026-68928 | HIGH | 8.6 | 0.2% | Sep 18, 2026 | Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.Term... |
| CVE-2026-63452 | HIGH | 7.5 | — | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now