2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90986 | HIGH | 7.1 | — | Sep 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions. |
| CVE-2026-90887 | HIGH | 7.1 | — | Sep 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions. |
| CVE-2026-89418 | HIGH | 8.7 | — | Sep 17, 2026 | google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small... |
| CVE-2026-82760 | HIGH | 8.2 | — | Sep 17, 2026 | Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to... |
| CVE-2026-82685 | HIGH | 7.6 | — | Sep 17, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated... |
| CVE-2026-81632 | HIGH | 7.2 | — | Sep 17, 2026 | Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone ab... |
| CVE-2026-81442 | HIGH | 8.1 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerabilit... |
| CVE-2026-80218 | HIGH | 7.6 | — | Sep 17, 2026 | Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for o... |
| CVE-2026-78295 | HIGH | 8.8 | — | Sep 17, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions. |
| CVE-2026-66631 | HIGH | 7.6 | — | Sep 17, 2026 | Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions. |
| CVE-2026-66630 | HIGH | 7.6 | 0.3% | Sep 17, 2026 | Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. |
| CVE-2026-66628 | HIGH | 7.6 | — | Sep 17, 2026 | Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions. |
| CVE-2026-66626 | HIGH | 7.6 | 0.3% | Sep 17, 2026 | Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. |
| CVE-2026-66625 | HIGH | 7.6 | — | Sep 17, 2026 | Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions. |
| CVE-2026-66624 | HIGH | 7.6 | — | Sep 17, 2026 | Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions. |
| CVE-2026-66619 | HIGH | 7.6 | 0.3% | Sep 17, 2026 | Administrator SQL Injection in Newsletters <= 4.18 versions. |
| CVE-2026-66618 | HIGH | 7.6 | — | Sep 17, 2026 | Administrator SQL Injection in WP Maps <= 4.9.9 versions. |
| CVE-2026-66580 | HIGH | 8.5 | — | Sep 17, 2026 | Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions. |
| CVE-2026-66571 | HIGH | 7.1 | — | Sep 17, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions. |
| CVE-2026-14850 | HIGH | 8.8 | — | Sep 17, 2026 | The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the use... |
| CVE-2026-92919 | HIGH | 8.1 | 0.4% | Sep 17, 2026 | admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to ... |
| CVE-2026-92918 | HIGH | 8.8 | 0.4% | Sep 17, 2026 | admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events... |
| CVE-2026-81481 | HIGH | 7.5 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Res... |
| CVE-2026-92925 | HIGH | 7.1 | 0.3% | Sep 17, 2026 | A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packet... |
| CVE-2026-92917 | HIGH | 7.5 | 0.3% | Sep 17, 2026 | Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now