2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-89413 | HIGH | 8.1 | — | Sep 18, 2026 | The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.... |
| CVE-2026-93485 | HIGH | 7.1 | 0.2% | Sep 18, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPre... |
| CVE-2026-90978 | HIGH | 7.1 | — | Sep 18, 2026 | The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonc... |
| CVE-2026-88825 | HIGH | 8.8 | — | Sep 18, 2026 | The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowin... |
| CVE-2026-87775 | HIGH | 8.6 | — | Sep 18, 2026 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to ... |
| CVE-2026-87774 | HIGH | 8.6 | — | Sep 18, 2026 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to ... |
| CVE-2026-87771 | HIGH | 8.6 | — | Sep 18, 2026 | The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them... |
| CVE-2026-87770 | HIGH | 8.6 | — | Sep 18, 2026 | The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using ... |
| CVE-2026-87767 | HIGH | 8.6 | — | Sep 18, 2026 | The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter bef... |
| CVE-2026-85127 | HIGH | 8.8 | — | Sep 18, 2026 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthentic... |
| CVE-2026-85122 | HIGH | 8.8 | — | Sep 18, 2026 | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stor... |
| CVE-2026-81810 | HIGH | 7.2 | — | Sep 18, 2026 | The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of... |
| CVE-2026-18912 | HIGH | 7.7 | — | Sep 18, 2026 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allo... |
| CVE-2026-18911 | HIGH | 7.5 | — | Sep 18, 2026 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolle... |
| CVE-2026-17086 | HIGH | 8.8 | — | Sep 18, 2026 | The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object I... |
| CVE-2026-93468 | HIGH | 7.5 | — | Sep 18, 2026 | The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit R... |
| CVE-2026-93371 | HIGH | 8.3 | 1.4% | Sep 18, 2026 | A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function Ne... |
| CVE-2026-93456 | HIGH | 8.2 | 0.2% | Sep 18, 2026 | django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing ... |
| CVE-2026-93331 | HIGH | 7.3 | — | Sep 18, 2026 | A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file ... |
| CVE-2026-79954 | HIGH | 8.7 | — | Sep 18, 2026 | NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiv... |
| CVE-2026-93453 | HIGH | 8.3 | 0.3% | Sep 18, 2026 | SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing u... |
| CVE-2026-93452 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that wr... |
| CVE-2026-93450 | HIGH | 7.5 | 0.7% | Sep 18, 2026 | go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serializatio... |
| CVE-2026-85887 | HIGH | 7.7 | — | Sep 18, 2026 | Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose informat... |
| CVE-2026-93436 | HIGH | 7.5 | 0.5% | Sep 17, 2026 | vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode di... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now