2026 CVE Vulnerabilities
65,368 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-89001 | MEDIUM | 4.9 | — | Sep 27, 2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not verify that a user running a feed campaign is per... |
| CVE-2026-89000 | MEDIUM | 4.1 | — | Sep 27, 2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.27 does not perform a capability check or validate the destin... |
| CVE-2026-86841 | MEDIUM | 4.7 | — | Sep 27, 2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not prevent deserialization of u... |
| CVE-2026-86839 | LOW | 3.8 | — | Sep 27, 2026 | The Online Scheduling and Appointment Booking System WordPress plugin before 28.3 does not verify that appointment and ... |
| CVE-2026-86609 | HIGH | 8.8 | — | Sep 27, 2026 | The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked ... |
| CVE-2026-85002 | MEDIUM | 6.8 | — | Sep 27, 2026 | The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an... |
| CVE-2026-84069 | MEDIUM | 5.3 | — | Sep 27, 2026 | The WebFacing™ WordPress plugin before 5.4 does not restrict access to one of its bundled scripts and does not validate... |
| CVE-2026-82841 | MEDIUM | 5.3 | — | Sep 27, 2026 | The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.8, UpdraftPlus: WP Backup & Migration Plugin ... |
| CVE-2026-81655 | HIGH | 7.5 | — | Sep 27, 2026 | The Ad Inserter WordPress plugin before 2.8.19 does not correctly restrict access to one of its settings pages, making ... |
| CVE-2026-100746 | HIGH | 7.3 | — | Sep 27, 2026 | A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /web... |
| CVE-2026-100865 | HIGH | 8.8 | — | Sep 27, 2026 | Heym before 0.0.53 evaluates workflow condition expressions using Python's eval() with insufficient sandboxing in the wo... |
| CVE-2026-100864 | HIGH | 8.8 | — | Sep 27, 2026 | heym before 0.0.91 contains a sandbox escape vulnerability in the expression engine's DotList map/filter and fallback re... |
| CVE-2026-100863 | MEDIUM | 5 | — | Sep 27, 2026 | Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/serv... |
| CVE-2026-100862 | MEDIUM | 4.9 | — | Sep 27, 2026 | heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0... |
| CVE-2026-100861 | MEDIUM | 5 | — | Sep 27, 2026 | heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowin... |
| CVE-2026-100860 | MEDIUM | 5.5 | — | Sep 27, 2026 | heym before 0.0.105 does not act on the result of the credential authorization lookup in the Redis workflow node (backen... |
| CVE-2026-100859 | MEDIUM | 6.5 | — | Sep 27, 2026 | Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that all... |
| CVE-2026-100858 | MEDIUM | 6.8 | — | Sep 27, 2026 | heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nod... |
| CVE-2026-100857 | HIGH | 8 | — | Sep 27, 2026 | AzuraCast before 0.23.4 contains a code injection vulnerability in the ConfigWriter::cleanUpString() method that fails t... |
| CVE-2026-100856 | HIGH | 8.8 | — | Sep 27, 2026 | AzuraCast before 0.23.6 contains a code injection vulnerability in the remote relay password field due to incomplete mig... |
| CVE-2026-100855 | MEDIUM | 6.5 | — | Sep 27, 2026 | AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}... |
| CVE-2026-100854 | MEDIUM | 6.3 | — | Sep 27, 2026 | AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derive... |
| CVE-2026-100853 | MEDIUM | 5.9 | — | Sep 27, 2026 | In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allow... |
| CVE-2026-100852 | HIGH | 8.8 | — | Sep 27, 2026 | AzuraCast before 0.23.8 contains a command injection vulnerability in the Liquidsoap config generation for live recordin... |
| CVE-2026-100851 | HIGH | 7.6 | — | Sep 27, 2026 | AzuraCast before 0.23.8 contains a broken access control vulnerability in the GET /api/station/{id}/vue/profile endpoint... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now