2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90922 | MEDIUM | 5.3 | — | Sep 17, 2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported b... |
| CVE-2026-86824 | MEDIUM | 4.8 | — | Sep 17, 2026 | The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy a... |
| CVE-2026-86788 | MEDIUM | 6.8 | — | Sep 17, 2026 | The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the s... |
| CVE-2026-50604 | MEDIUM | 4.9 | — | Sep 17, 2026 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The ... |
| CVE-2026-92839 | MEDIUM | 4.3 | — | Sep 17, 2026 | Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the applicat... |
| CVE-2026-86311 | MEDIUM | 6.4 | — | Sep 17, 2026 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scrip... |
| CVE-2026-50603 | MEDIUM | 4.9 | — | Sep 17, 2026 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The ... |
| CVE-2026-89064 | MEDIUM | 5.3 | — | Sep 17, 2026 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versi... |
| CVE-2026-61589 | MEDIUM | 6.3 | — | Sep 16, 2026 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ... |
| CVE-2026-61588 | MEDIUM | 6.5 | 0.4% | Sep 16, 2026 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ... |
| CVE-2026-92598 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain... |
| CVE-2026-92597 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a commen... |
| CVE-2026-92595 | MEDIUM | 5.9 | 0.2% | Sep 16, 2026 | Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAcc... |
| CVE-2026-92591 | MEDIUM | 5.9 | 0.2% | Sep 16, 2026 | Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes... |
| CVE-2026-92590 | MEDIUM | 5.4 | 0.1% | Sep 16, 2026 | Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields... |
| CVE-2026-92589 | MEDIUM | 4.3 | 0.2% | Sep 16, 2026 | Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder ... |
| CVE-2026-92588 | MEDIUM | 4.4 | 0.2% | Sep 16, 2026 | n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endp... |
| CVE-2026-92587 | MEDIUM | 5 | 0.2% | Sep 16, 2026 | n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relativ... |
| CVE-2026-92586 | MEDIUM | 4.3 | 0.2% | Sep 16, 2026 | AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the se... |
| CVE-2026-92585 | MEDIUM | 4.3 | 0.2% | Sep 16, 2026 | AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the ... |
| CVE-2026-92584 | MEDIUM | 6.1 | 0.2% | Sep 16, 2026 | AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticat... |
| CVE-2026-92583 | MEDIUM | 6.5 | 0.2% | Sep 16, 2026 | AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate... |
| CVE-2026-92581 | MEDIUM | 4.3 | 0.2% | Sep 16, 2026 | In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowin... |
| CVE-2026-92579 | MEDIUM | 5.4 | 0.2% | Sep 16, 2026 | In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without ... |
| CVE-2026-89034 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low En... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now