2026 CVE Vulnerabilities
65,801 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97228 | LOW | 2.7 | — | Sep 25, 2026 | Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status com... |
| CVE-2026-27867 | MEDIUM | 4.8 | — | Sep 25, 2026 | An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration actio... |
| CVE-2026-97898 | HIGH | 8.4 | — | Sep 25, 2026 | Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unloc... |
| CVE-2026-92106 | LOW | 2.3 | — | Sep 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_htm... |
| CVE-2026-97863 | MEDIUM | 6.3 | 0.3% | Sep 25, 2026 | The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to ... |
| CVE-2026-92573 | MEDIUM | 6.5 | — | Sep 25, 2026 | Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message d... |
| CVE-2026-92564 | HIGH | 7.5 | 0.2% | Sep 25, 2026 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of... |
| CVE-2026-92560 | HIGH | 7.5 | — | Sep 25, 2026 | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential... |
| CVE-2026-92550 | HIGH | 7.5 | — | Sep 25, 2026 | A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential... |
| CVE-2026-88848 | MEDIUM | 4.2 | — | Sep 25, 2026 | The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is c... |
| CVE-2026-86837 | MEDIUM | 5.3 | — | Sep 25, 2026 | The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored deta... |
| CVE-2026-80514 | MEDIUM | 5.3 | — | Sep 25, 2026 | The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address heade... |
| CVE-2026-6088 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6087 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6086 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6085 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6084 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6083 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6082 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-96752 | HIGH | 7.2 | — | Sep 25, 2026 | The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys... |
| CVE-2026-96568 | HIGH | 7.2 | — | Sep 25, 2026 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_n... |
| CVE-2026-96448 | MEDIUM | 6.6 | 0.2% | Sep 25, 2026 | A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management ... |
| CVE-2026-95866 | HIGH | 7.2 | — | Sep 25, 2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2026-95864 | HIGH | 7.2 | — | Sep 25, 2026 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'css[fonts]' Parameter in all ... |
| CVE-2026-94573 | HIGH | 7.2 | — | Sep 25, 2026 | The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater F... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now