2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92932 | MEDIUM | 5.1 | — | Sep 17, 2026 | In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in... |
| CVE-2026-92921 | MEDIUM | 4.9 | 0.2% | Sep 17, 2026 | admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivatio... |
| CVE-2026-92920 | MEDIUM | 5.4 | 0.2% | Sep 17, 2026 | admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain a... |
| CVE-2026-92904 | MEDIUM | 4.3 | — | Sep 17, 2026 | A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_... |
| CVE-2026-92912 | MEDIUM | 6.5 | 0.2% | Sep 17, 2026 | AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish key... |
| CVE-2026-81479 | MEDIUM | 5.8 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A ... |
| CVE-2026-81441 | MEDIUM | 4 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Functio... |
| CVE-2026-78296 | MEDIUM | 5.3 | 0.1% | Sep 17, 2026 | Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. ... |
| CVE-2026-92893 | MEDIUM | 4.3 | — | Sep 17, 2026 | A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an un... |
| CVE-2026-92611 | MEDIUM | 4.8 | — | Sep 17, 2026 | In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at... |
| CVE-2026-92894 | MEDIUM | 4.3 | — | Sep 17, 2026 | A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target Loo... |
| CVE-2026-78427 | MEDIUM | 4.3 | — | Sep 17, 2026 | The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of... |
| CVE-2026-87831 | MEDIUM | 4.3 | — | Sep 17, 2026 | The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate t... |
| CVE-2026-87829 | MEDIUM | 4.3 | — | Sep 17, 2026 | The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate t... |
| CVE-2026-90982 | MEDIUM | 5.3 | — | Sep 17, 2026 | @fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4... |
| CVE-2026-44940 | MEDIUM | 5.7 | — | Sep 17, 2026 | The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecu... |
| CVE-2026-91019 | MEDIUM | 4.9 | — | Sep 17, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payme... |
| CVE-2026-91016 | MEDIUM | 5.3 | — | Sep 17, 2026 | The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published ... |
| CVE-2026-91015 | MEDIUM | 5.3 | — | Sep 17, 2026 | The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX actio... |
| CVE-2026-91011 | MEDIUM | 6.8 | — | Sep 17, 2026 | The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites ... |
| CVE-2026-91010 | MEDIUM | 4.3 | — | Sep 17, 2026 | The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the... |
| CVE-2026-91009 | MEDIUM | 4.3 | — | Sep 17, 2026 | The Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin before 2.1.3 does not have authorisation an... |
| CVE-2026-90923 | MEDIUM | 6.5 | — | Sep 17, 2026 | The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unaut... |
| CVE-2026-90922 | MEDIUM | 5.3 | — | Sep 17, 2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported b... |
| CVE-2026-86824 | MEDIUM | 4.8 | — | Sep 17, 2026 | The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now