2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92410 | MEDIUM | 4.3 | 0.1% | Sep 20, 2026 | The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up del... |
| CVE-2026-87840 | MEDIUM | 5.3 | 0.1% | Sep 20, 2026 | The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative boo... |
| CVE-2026-87068 | MEDIUM | 6.6 | 0.1% | Sep 20, 2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a r... |
| CVE-2026-84223 | MEDIUM | 6.8 | 0.2% | Sep 20, 2026 | The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, al... |
| CVE-2026-81653 | MEDIUM | 4.2 | 0.1% | Sep 20, 2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an imag... |
| CVE-2026-16542 | MEDIUM | 4.1 | 0.1% | Sep 20, 2026 | The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before req... |
| CVE-2026-14844 | MEDIUM | 6.8 | 0.2% | Sep 20, 2026 | The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before ... |
| CVE-2026-93965 | MEDIUM | 6.6 | 1.6% | Sep 20, 2026 | A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops... |
| CVE-2026-93964 | MEDIUM | 5.3 | 0.3% | Sep 20, 2026 | A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCe... |
| CVE-2026-93963 | MEDIUM | 6.3 | 0.2% | Sep 20, 2026 | A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function... |
| CVE-2026-93961 | MEDIUM | 5.3 | 0.4% | Sep 20, 2026 | A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of... |
| CVE-2026-93960 | MEDIUM | 4.3 | 0.4% | Sep 20, 2026 | A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Co... |
| CVE-2026-86552 | MEDIUM | 5.4 | 0.3% | Sep 20, 2026 | SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acqui... |
| CVE-2026-93957 | MEDIUM | 4.3 | 0.3% | Sep 20, 2026 | A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleF... |
| CVE-2026-94057 | MEDIUM | 5.3 | 0.3% | Sep 19, 2026 | Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead dep... |
| CVE-2026-94055 | MEDIUM | 5.3 | 0.4% | Sep 19, 2026 | Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. |
| CVE-2026-94054 | MEDIUM | 5.3 | 0.3% | Sep 19, 2026 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. |
| CVE-2026-93988 | MEDIUM | 6.5 | 0.4% | Sep 19, 2026 | QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows a... |
| CVE-2026-93955 | MEDIUM | 4.3 | 0.4% | Sep 19, 2026 | A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the functio... |
| CVE-2026-93954 | MEDIUM | 4.3 | 0.4% | Sep 19, 2026 | A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSet... |
| CVE-2026-82672 | MEDIUM | 6.3 | 0.3% | Sep 19, 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allow... |
| CVE-2026-94001 | MEDIUM | 6.5 | 0.3% | Sep 19, 2026 | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint... |
| CVE-2026-94000 | MEDIUM | 6.6 | 0.2% | Sep 19, 2026 | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue oc... |
| CVE-2026-93999 | MEDIUM | 4.2 | 0.1% | Sep 19, 2026 | A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution... |
| CVE-2026-93984 | MEDIUM | 5.3 | 0.2% | Sep 19, 2026 | OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptograph... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now