2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-87119 | HIGH | 8.2 | — | Sep 22, 2026 | Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation cre... |
| CVE-2026-94117 | HIGH | 7.6 | — | Sep 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar –... |
| CVE-2026-90882 | HIGH | 8.7 | — | Sep 22, 2026 | The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-C... |
| CVE-2026-25265 | HIGH | 8.8 | 0.1% | Sep 22, 2026 | Privilege escalation due to weak configuration while temporary file handling. |
| CVE-2026-25264 | HIGH | 8.8 | 0.1% | Sep 22, 2026 | Privilege escalation due to weak configuration during package extraction process. |
| CVE-2026-25255 | HIGH | 8.8 | — | Sep 22, 2026 | Exposed dangerous function lead to privilege escalation via gRPC server. |
| CVE-2026-9231 | HIGH | 7.5 | 0.6% | Sep 22, 2026 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inc... |
| CVE-2026-95508 | HIGH | 7.4 | 0.4% | Sep 22, 2026 | A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured... |
| CVE-2026-93928 | HIGH | 7.3 | 0.3% | Sep 22, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCo... |
| CVE-2026-68956 | HIGH | 7.1 | 0.7% | Sep 22, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote atta... |
| CVE-2026-65634 | HIGH | 8.2 | 0.4% | Sep 22, 2026 | Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated atta... |
| CVE-2026-93836 | HIGH | 7.2 | 0.2% | Sep 22, 2026 | The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qty' ... |
| CVE-2026-93778 | HIGH | 7.2 | 0.2% | Sep 22, 2026 | The WP Yelp Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Yelp Review Text (import... |
| CVE-2026-92969 | HIGH | 8.1 | 0.7% | Sep 22, 2026 | The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in a... |
| CVE-2026-92235 | HIGH | 8.1 | 0.4% | Sep 22, 2026 | The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, an... |
| CVE-2026-87082 | HIGH | 7.5 | 0.2% | Sep 22, 2026 | Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in... |
| CVE-2026-87081 | HIGH | 7.5 | 0.2% | Sep 22, 2026 | Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label... |
| CVE-2026-87079 | HIGH | 7.5 | 0.2% | Sep 22, 2026 | Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long... |
| CVE-2026-74766 | HIGH | 8.4 | 0.2% | Sep 22, 2026 | Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that r... |
| CVE-2026-6922 | HIGH | 7.1 | 0.3% | Sep 22, 2026 | The WP Table Builder – Drag & Drop Table Builder plugin for WordPress is vulnerable to Incorrect Authorization in all ve... |
| CVE-2026-94504 | HIGH | 7.2 | 0.3% | Sep 22, 2026 | Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy su... |
| CVE-2026-92438 | HIGH | 8.8 | 0.3% | Sep 22, 2026 | The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submis... |
| CVE-2026-91827 | HIGH | 7.5 | 0.3% | Sep 22, 2026 | The Ninja Forms WordPress plugin 3.15.3 does not prevent user-submitted form field values from being deserialised when a... |
| CVE-2026-89412 | HIGH | 7.2 | 0.3% | Sep 22, 2026 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2026-12470 | HIGH | 7.2 | 0.3% | Sep 22, 2026 | The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to unauthorized modificatio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now