2026 CVE Vulnerabilities
64,824 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27559 | HIGH | 8.8 | 2.1% | Sep 16, 2026 | A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sendi... |
| CVE-2026-27558 | HIGH | 8.8 | 2.1% | Sep 16, 2026 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/aj... |
| CVE-2026-27557 | HIGH | 7.5 | 0.7% | Sep 16, 2026 | An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file ... |
| CVE-2026-27556 | HIGH | 8.8 | 0.9% | Sep 16, 2026 | A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_param... |
| CVE-2026-27555 | HIGH | 8.8 | 0.8% | Sep 16, 2026 | A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_i... |
| CVE-2026-27554 | HIGH | 8.8 | 2.1% | Sep 16, 2026 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_paramete... |
| CVE-2026-27552 | HIGH | 8.1 | 0.6% | Sep 16, 2026 | A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload end... |
| CVE-2026-27551 | HIGH | 8.8 | 2.1% | Sep 16, 2026 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage en... |
| CVE-2026-27550 | HIGH | 8.8 | 2.1% | Sep 16, 2026 | A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using ... |
| CVE-2026-27549 | HIGH | 8.8 | 2.1% | Sep 16, 2026 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do... |
| CVE-2026-27548 | HIGH | 8.8 | 2.1% | Sep 16, 2026 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info... |
| CVE-2026-27547 | HIGH | 8.8 | 2.1% | Sep 16, 2026 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info... |
| CVE-2026-79708 | HIGH | 8.5 | 0.3% | Sep 16, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3... |
| CVE-2026-78252 | HIGH | 8.2 | 0.4% | Sep 16, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 1... |
| CVE-2026-1168 | HIGH | 7.5 | 0.6% | Sep 16, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and... |
| CVE-2026-19248 | HIGH | 7.1 | 0.4% | Sep 16, 2026 | QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input... |
| CVE-2026-86444 | HIGH | 7.1 | 0.2% | Sep 16, 2026 | The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute... |
| CVE-2026-85569 | HIGH | 7.2 | 0.2% | Sep 16, 2026 | The Tutor LMS WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addressed to it... |
| CVE-2026-85530 | HIGH | 8.1 | 0.2% | Sep 16, 2026 | The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value ... |
| CVE-2026-84829 | HIGH | 8.8 | 0.2% | Sep 16, 2026 | The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an ... |
| CVE-2026-78472 | HIGH | 8.6 | 0.2% | Sep 16, 2026 | The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it ... |
| CVE-2026-76552 | HIGH | 8.8 | 0.3% | Sep 16, 2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it re... |
| CVE-2026-76551 | HIGH | 7.2 | 0.3% | Sep 16, 2026 | The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported... |
| CVE-2026-76550 | HIGH | 7.2 | 0.3% | Sep 16, 2026 | The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing expo... |
| CVE-2026-74926 | HIGH | 7.1 | 0.2% | Sep 16, 2026 | The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now