2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-89093 | MEDIUM | 5.3 | 0.3% | Sep 19, 2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Info... |
| CVE-2026-89081 | MEDIUM | 6.1 | 0.2% | Sep 19, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin... |
| CVE-2026-88944 | MEDIUM | 4.3 | 0.3% | Sep 19, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all v... |
| CVE-2026-15760 | MEDIUM | 6.5 | 0.2% | Sep 19, 2026 | The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including... |
| CVE-2026-15660 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7. Thi... |
| CVE-2026-12042 | MEDIUM | 4.4 | 0.2% | Sep 19, 2026 | The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v... |
| CVE-2026-77820 | MEDIUM | 6.4 | 0.2% | Sep 19, 2026 | The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all ... |
| CVE-2026-93921 | MEDIUM | 4.3 | 0.2% | Sep 19, 2026 | SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only ... |
| CVE-2026-77875 | MEDIUM | 6.8 | 0.2% | Sep 19, 2026 | The application protects access through its calculator-style vault passcode, but the stored data is not bound to that au... |
| CVE-2026-93574 | MEDIUM | 6.5 | 0.5% | Sep 18, 2026 | A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending ... |
| CVE-2026-93562 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote... |
| CVE-2026-85272 | MEDIUM | 4.3 | 0.5% | Sep 18, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawo... |
| CVE-2026-85271 | MEDIUM | 6.1 | 0.4% | Sep 18, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. From Redwood until Ulmo and Verawo... |
| CVE-2026-71855 | MEDIUM | 5.9 | 0.5% | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2026-63448 | MEDIUM | 5.9 | 0.4% | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2026-61670 | MEDIUM | 6.5 | 0.1% | Sep 18, 2026 | microsandbox is an easy, fast, local-first microVM runtime and library. Prior to 0.5.10, sdk/rust/lib/runtime/spawn.rs s... |
| CVE-2026-57229 | MEDIUM | 5.3 | 0.4% | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr... |
| CVE-2026-93873 | MEDIUM | 4.3 | 0.2% | Sep 18, 2026 | Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to... |
| CVE-2026-93871 | MEDIUM | 5.4 | 0.2% | Sep 18, 2026 | Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticate... |
| CVE-2026-93870 | MEDIUM | 4.3 | 0.1% | Sep 18, 2026 | Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge... |
| CVE-2026-93869 | MEDIUM | 6.1 | 0.2% | Sep 18, 2026 | Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect de... |
| CVE-2026-93838 | MEDIUM | 5.9 | 0.5% | Sep 18, 2026 | SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails t... |
| CVE-2026-91205 | MEDIUM | 6 | 0.1% | Sep 18, 2026 | A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation ... |
| CVE-2026-91203 | MEDIUM | 6 | 0.1% | Sep 18, 2026 | A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a syml... |
| CVE-2026-91202 | MEDIUM | 6.1 | 0.1% | Sep 18, 2026 | A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory co... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now