2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93563 | HIGH | 7.5 | 0.6% | Sep 18, 2026 | A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-midd... |
| CVE-2026-81627 | HIGH | 8.2 | 0.2% | Sep 18, 2026 | A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias rem... |
| CVE-2026-87915 | HIGH | 7.2 | — | Sep 18, 2026 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ... |
| CVE-2026-87743 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normal... |
| CVE-2026-18405 | HIGH | 7.2 | — | Sep 18, 2026 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul... |
| CVE-2026-15579 | HIGH | 8.8 | — | Sep 18, 2026 | An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the usern... |
| CVE-2026-85410 | HIGH | 8.1 | 0.3% | Sep 18, 2026 | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template... |
| CVE-2026-83561 | HIGH | 7.2 | — | Sep 18, 2026 | The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comm... |
| CVE-2026-6205 | HIGH | 8.1 | — | Sep 18, 2026 | An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-... |
| CVE-2026-40539 | HIGH | 7.1 | — | Sep 18, 2026 | An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-1... |
| CVE-2026-40530 | HIGH | 8 | — | Sep 18, 2026 | An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manage... |
| CVE-2026-13673 | HIGH | 8.8 | — | Sep 18, 2026 | An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM)... |
| CVE-2026-93494 | HIGH | 7.5 | 0.6% | Sep 18, 2026 | A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending ... |
| CVE-2026-89059 | HIGH | 7.5 | — | Sep 18, 2026 | A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing ... |
| CVE-2026-89058 | HIGH | 7.4 | 0.3% | Sep 18, 2026 | A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Ori... |
| CVE-2026-85705 | HIGH | 7.5 | — | Sep 18, 2026 | The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API... |
| CVE-2026-75157 | HIGH | 7.5 | 0.2% | Sep 18, 2026 | Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `E... |
| CVE-2026-67103 | HIGH | 7.6 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to ... |
| CVE-2026-67102 | HIGH | 8.1 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a lo... |
| CVE-2026-18442 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injecti... |
| CVE-2026-15275 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_searc... |
| CVE-2026-14323 | HIGH | 7.5 | — | Sep 18, 2026 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in... |
| CVE-2026-12954 | HIGH | 8.8 | 0.5% | Sep 18, 2026 | The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including... |
| CVE-2026-12384 | HIGH | 8.8 | — | Sep 18, 2026 | Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. ... |
| CVE-2026-92619 | HIGH | 7.2 | — | Sep 18, 2026 | The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now