2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90990 | MEDIUM | 5.3 | — | Sep 22, 2026 | Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 a... |
| CVE-2026-25262 | MEDIUM | 6.9 | — | Sep 22, 2026 | Memory corruption while processing a crafted ELF file in the Primary Bootloader. |
| CVE-2026-15095 | MEDIUM | 4.9 | 1.2% | Sep 22, 2026 | The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vu... |
| CVE-2026-9004 | MEDIUM | 4.3 | 0.2% | Sep 22, 2026 | The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in ... |
| CVE-2026-95503 | MEDIUM | 6.8 | 0.1% | Sep 22, 2026 | A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution... |
| CVE-2026-91092 | MEDIUM | 4.3 | 0.2% | Sep 22, 2026 | The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5.... |
| CVE-2026-7622 | MEDIUM | 4.3 | 0.2% | Sep 22, 2026 | The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is ... |
| CVE-2026-74765 | MEDIUM | 6.5 | 0.2% | Sep 22, 2026 | Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumula... |
| CVE-2026-4123 | MEDIUM | 4.3 | 0.2% | Sep 22, 2026 | The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in all versions up to and i... |
| CVE-2026-1645 | MEDIUM | 4.4 | 0.2% | Sep 22, 2026 | The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_currency' parameter and the... |
| CVE-2026-18439 | MEDIUM | 4.3 | 0.3% | Sep 22, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere... |
| CVE-2026-18345 | MEDIUM | 4.3 | 0.2% | Sep 22, 2026 | The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2026-16778 | MEDIUM | 6.4 | 0.2% | Sep 22, 2026 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2026-12995 | MEDIUM | 4.3 | 0.2% | Sep 22, 2026 | The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ... |
| CVE-2026-93655 | MEDIUM | 6.1 | 0.2% | Sep 22, 2026 | The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' param... |
| CVE-2026-88788 | MEDIUM | 6.8 | 0.2% | Sep 22, 2026 | The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputti... |
| CVE-2026-85653 | MEDIUM | 6.4 | 0.3% | Sep 22, 2026 | The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'other_attributes' Bl... |
| CVE-2026-94492 | MEDIUM | 6.3 | 0.2% | Sep 22, 2026 | A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u... |
| CVE-2026-93711 | MEDIUM | 6.5 | 0.2% | Sep 22, 2026 | Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routi... |
| CVE-2026-93709 | MEDIUM | 5.3 | 0.2% | Sep 22, 2026 | Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard... |
| CVE-2026-76974 | MEDIUM | 5.3 | 0.2% | Sep 22, 2026 | SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craf... |
| CVE-2026-94490 | MEDIUM | 4.7 | 2.1% | Sep 22, 2026 | A security flaw has been discovered in OctoPrint 1.0.0. Affected by this issue is the function executeSystemCommand of t... |
| CVE-2026-94489 | MEDIUM | 4.3 | 0.4% | Sep 22, 2026 | A vulnerability was identified in OctoPrint 1.0.0. Affected by this vulnerability is the function _validate of the file ... |
| CVE-2026-94625 | MEDIUM | 5.3 | 0.3% | Sep 21, 2026 | vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests cr... |
| CVE-2026-94536 | MEDIUM | 4.3 | 0.2% | Sep 21, 2026 | lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now