2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93959 | HIGH | 7.3 | 0.4% | Sep 20, 2026 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown ... |
| CVE-2026-94056 | HIGH | 7.5 | 0.4% | Sep 19, 2026 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uni... |
| CVE-2026-93993 | HIGH | 8.8 | 0.6% | Sep 19, 2026 | Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes... |
| CVE-2026-93992 | HIGH | 8.1 | 0.8% | Sep 19, 2026 | Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write... |
| CVE-2026-93991 | HIGH | 7.7 | 0.3% | Sep 19, 2026 | Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that ... |
| CVE-2026-93990 | HIGH | 7.5 | 0.3% | Sep 19, 2026 | Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-1... |
| CVE-2026-82560 | HIGH | 7.5 | 0.6% | Sep 19, 2026 | Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting d... |
| CVE-2026-1255 | HIGH | 7.5 | 0.3% | Sep 19, 2026 | The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including... |
| CVE-2026-85658 | HIGH | 8.1 | 0.4% | Sep 19, 2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres... |
| CVE-2026-4327 | HIGH | 8.8 | 0.7% | Sep 19, 2026 | The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1... |
| CVE-2026-15664 | HIGH | 7.2 | 0.4% | Sep 19, 2026 | The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2026-92404 | HIGH | 7.5 | 0.3% | Sep 19, 2026 | The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowi... |
| CVE-2026-88926 | HIGH | 8.6 | 0.3% | Sep 19, 2026 | The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of it... |
| CVE-2026-88824 | HIGH | 8.8 | 0.3% | Sep 19, 2026 | The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthe... |
| CVE-2026-86814 | HIGH | 8.1 | 0.2% | Sep 19, 2026 | The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an e... |
| CVE-2026-85680 | HIGH | 8.8 | 0.3% | Sep 19, 2026 | The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names bef... |
| CVE-2026-85574 | HIGH | 8 | 0.2% | Sep 19, 2026 | The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the conf... |
| CVE-2026-76790 | HIGH | 7.1 | 0.1% | Sep 19, 2026 | The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a ... |
| CVE-2026-76554 | HIGH | 7.2 | 0.3% | Sep 19, 2026 | The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to... |
| CVE-2026-92807 | HIGH | 8.8 | 0.3% | Sep 19, 2026 | The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions u... |
| CVE-2026-87909 | HIGH | 7.5 | 0.5% | Sep 19, 2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_m... |
| CVE-2026-13354 | HIGH | 7.2 | 0.2% | Sep 19, 2026 | The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Cont... |
| CVE-2026-93923 | HIGH | 8.8 | 0.4% | Sep 19, 2026 | SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing st... |
| CVE-2026-93922 | HIGH | 8.8 | 0.5% | Sep 19, 2026 | SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing store... |
| CVE-2026-88097 | HIGH | 7.8 | 0.3% | Sep 18, 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now