2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-94176 | HIGH | 7.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions. |
| CVE-2026-94174 | HIGH | 7.6 | — | Sep 23, 2026 | Administrator SQL Injection in Email Log <= 2.63 versions. |
| CVE-2026-94124 | HIGH | 8.5 | — | Sep 23, 2026 | Contributor SQL Injection in WP EasyCart <= 5.9.4 versions. |
| CVE-2026-93774 | HIGH | 7.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions. |
| CVE-2026-93773 | HIGH | 8.5 | — | Sep 23, 2026 | Contributor SQL Injection in Mollie Forms <= 2.11.0 versions. |
| CVE-2026-93622 | HIGH | 7.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions. |
| CVE-2026-93527 | HIGH | 8.5 | — | Sep 23, 2026 | Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions. |
| CVE-2026-93526 | HIGH | 7.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions. |
| CVE-2026-92730 | HIGH | 7.4 | — | Sep 23, 2026 | LimeSurvey Community Edition 7.0.14 contains a reflected cross-site scripting vulnerability on the administrative survey... |
| CVE-2026-90905 | HIGH | 7.2 | — | Sep 23, 2026 | Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension... |
| CVE-2026-90904 | HIGH | 8.6 | — | Sep 23, 2026 | Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store ext... |
| CVE-2026-90903 | HIGH | 7.2 | — | Sep 23, 2026 | Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Stor... |
| CVE-2026-90902 | HIGH | 8.6 | 0.2% | Sep 23, 2026 | Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extensio... |
| CVE-2026-90901 | HIGH | 8.6 | 0.4% | Sep 23, 2026 | Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extens... |
| CVE-2026-90899 | HIGH | 8.2 | — | Sep 23, 2026 | Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.... |
| CVE-2026-84499 | HIGH | 7.7 | 0.4% | Sep 23, 2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are ... |
| CVE-2026-84486 | HIGH | 8.2 | — | Sep 23, 2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the inte... |
| CVE-2026-82368 | HIGH | 8.7 | 0.3% | Sep 23, 2026 | Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrat... |
| CVE-2026-82356 | HIGH | 7.5 | 0.1% | Sep 23, 2026 | Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificat... |
| CVE-2026-77601 | HIGH | 8.8 | — | Sep 23, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-77423 | HIGH | 7.5 | — | Sep 23, 2026 | JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in less viewer p... |
| CVE-2026-77422 | HIGH | 7.5 | — | Sep 23, 2026 | JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command ... |
| CVE-2026-77394 | HIGH | 7.6 | — | Sep 23, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-76648 | HIGH | 8.5 | 0.2% | Sep 23, 2026 | CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs n... |
| CVE-2026-76089 | HIGH | 7.7 | — | Sep 23, 2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-rese... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now