2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-94036 | HIGH | 8.8 | 0.5% | Sep 20, 2026 | A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element i... |
| CVE-2026-94015 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the... |
| CVE-2026-94109 | HIGH | 8 | 0.5% | Sep 20, 2026 | openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injection vulnerability in FreemarkerP... |
| CVE-2026-94107 | HIGH | 8.1 | 0.4% | Sep 20, 2026 | NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that gene... |
| CVE-2026-94106 | HIGH | 8.8 | 1.7% | Sep 20, 2026 | getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames ... |
| CVE-2026-94104 | HIGH | 8.8 | 0.7% | Sep 20, 2026 | NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails t... |
| CVE-2026-94004 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_j... |
| CVE-2026-93997 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown ... |
| CVE-2026-93980 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown cod... |
| CVE-2026-93979 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of t... |
| CVE-2026-93978 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown... |
| CVE-2026-93974 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A flaw has been found in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the f... |
| CVE-2026-93973 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown... |
| CVE-2026-93972 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element... |
| CVE-2026-93970 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the fil... |
| CVE-2026-93969 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_sup... |
| CVE-2026-92541 | HIGH | 7.2 | 0.1% | Sep 20, 2026 | The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in... |
| CVE-2026-92540 | HIGH | 7.2 | 0.1% | Sep 20, 2026 | The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users cap... |
| CVE-2026-87839 | HIGH | 7.5 | 0.1% | Sep 20, 2026 | The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of t... |
| CVE-2026-87067 | HIGH | 8.5 | 0.2% | Sep 20, 2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deser... |
| CVE-2026-85017 | HIGH | 7.5 | 0.1% | Sep 20, 2026 | The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX actio... |
| CVE-2026-82842 | HIGH | 8.1 | 0.1% | Sep 20, 2026 | The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming ... |
| CVE-2026-81650 | HIGH | 7.2 | 0.1% | Sep 20, 2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of f... |
| CVE-2026-93962 | HIGH | 8.3 | 0.5% | Sep 20, 2026 | A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_... |
| CVE-2026-86553 | HIGH | 8.8 | 0.4% | Sep 20, 2026 | SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Us... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now