2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85130 | HIGH | 8.8 | — | Sep 17, 2026 | The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for t... |
| CVE-2026-85128 | HIGH | 7.5 | — | Sep 17, 2026 | The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration ... |
| CVE-2026-87935 | HIGH | 8.1 | 0.5% | Sep 17, 2026 | The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1... |
| CVE-2026-25294 | HIGH | 7.4 | 0.2% | Sep 17, 2026 | Transient DOS while parsing frame during channel usage. |
| CVE-2026-25290 | HIGH | 7.8 | 0.1% | Sep 17, 2026 | Memory Corruption when validating large data buffers from external sources using addition to check buffer length. |
| CVE-2026-25284 | HIGH | 7.3 | 0.1% | Sep 17, 2026 | Information Disclosure when a pointer is reused after being deallocated. |
| CVE-2026-25283 | HIGH | 8.8 | 0.1% | Sep 17, 2026 | Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size. |
| CVE-2026-25282 | HIGH | 7.9 | 0.1% | Sep 17, 2026 | Transient DOS when processing unverified data from a neighboring system causes out of bound memory access. |
| CVE-2026-25281 | HIGH | 7.4 | 0.2% | Sep 17, 2026 | Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation. |
| CVE-2026-25280 | HIGH | 7.8 | 0.1% | Sep 17, 2026 | Memory corruption when processing escape handling flow with insufficient user buffer sizes. |
| CVE-2026-25278 | HIGH | 7 | 0.1% | Sep 17, 2026 | Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copyi... |
| CVE-2026-25275 | HIGH | 7.5 | 0.3% | Sep 17, 2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. |
| CVE-2026-25261 | HIGH | 7.8 | 0.1% | Sep 17, 2026 | Memory corruption while processing rear sensor IOCTL calls. |
| CVE-2026-24081 | HIGH | 7.4 | 0.2% | Sep 17, 2026 | Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enab... |
| CVE-2026-24075 | HIGH | 7 | 0.1% | Sep 17, 2026 | Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper sy... |
| CVE-2026-24074 | HIGH | 7.8 | 0.2% | Sep 17, 2026 | Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operat... |
| CVE-2026-24073 | HIGH | 7.8 | 0.2% | Sep 17, 2026 | Memory corruption when processing decode statistics due to insufficient validation of offset against structure size. |
| CVE-2026-92838 | HIGH | 7.8 | — | Sep 17, 2026 | A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or ... |
| CVE-2026-81546 | HIGH | 7.7 | — | Sep 17, 2026 | The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when pa... |
| CVE-2026-65388 | HIGH | 7.5 | — | Sep 16, 2026 | A remote attacker who controls a container registry may be able to direct a client's token request to a host of the atta... |
| CVE-2026-61599 | HIGH | 8.8 | — | Sep 16, 2026 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ... |
| CVE-2026-61596 | HIGH | 7.1 | — | Sep 16, 2026 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ... |
| CVE-2026-92599 | HIGH | 7.5 | 0.3% | Sep 16, 2026 | joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression de... |
| CVE-2026-92596 | HIGH | 7.5 | 0.5% | Sep 16, 2026 | Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows re... |
| CVE-2026-92594 | HIGH | 7.5 | 0.3% | Sep 16, 2026 | Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now