2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73192 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when usin... |
| CVE-2026-95625 | MEDIUM | 5.9 | 0.2% | Sep 23, 2026 | The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binar... |
| CVE-2026-92378 | MEDIUM | 4.1 | 0.2% | Sep 23, 2026 | A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Und... |
| CVE-2026-91817 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded P... |
| CVE-2026-91814 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents... |
| CVE-2026-91810 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF image masks.... |
| CVE-2026-91808 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inc... |
| CVE-2026-91807 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed image soft-mask ... |
| CVE-2026-91796 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows special... |
| CVE-2026-91788 | MEDIUM | 4.7 | 0.1% | Sep 23, 2026 | When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks r... |
| CVE-2026-50228 | MEDIUM | 6.1 | 0.1% | Sep 23, 2026 | An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (ver... |
| CVE-2026-50227 | MEDIUM | 6.1 | 0.3% | Sep 23, 2026 | An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSens... |
| CVE-2026-6831 | MEDIUM | 6.5 | 0.4% | Sep 23, 2026 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and in... |
| CVE-2026-5924 | MEDIUM | 6.4 | 0.3% | Sep 23, 2026 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps bloc... |
| CVE-2026-93511 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment... |
| CVE-2026-93510 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or res... |
| CVE-2026-91073 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputti... |
| CVE-2026-91025 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager W... |
| CVE-2026-91024 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iC... |
| CVE-2026-90985 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection ... |
| CVE-2026-89331 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token... |
| CVE-2026-88997 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it i... |
| CVE-2026-88929 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a produc... |
| CVE-2026-87981 | MEDIUM | 4.7 | 0.2% | Sep 23, 2026 | The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX acti... |
| CVE-2026-87979 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now