2026 CVE Vulnerabilities
65,819 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84279 | HIGH | 7.2 | — | Sep 25, 2026 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' par... |
| CVE-2026-83591 | HIGH | 7.2 | — | Sep 25, 2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment ... |
| CVE-2026-78397 | MEDIUM | 4 | — | Sep 25, 2026 | The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling b... |
| CVE-2026-78394 | MEDIUM | 4.1 | — | Sep 25, 2026 | The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a gen... |
| CVE-2026-78393 | MEDIUM | 6.1 | — | Sep 25, 2026 | The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the ad... |
| CVE-2026-75553 | LOW | 2.4 | 0.1% | Sep 25, 2026 | Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an att... |
| CVE-2026-62062 | HIGH | 8.8 | — | Sep 25, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This is... |
| CVE-2026-19775 | MEDIUM | 4.3 | — | Sep 25, 2026 | The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorizat... |
| CVE-2026-14281 | CRITICAL | 9.8 | — | Sep 25, 2026 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulne... |
| CVE-2026-97721 | LOW | 2.7 | 0.2% | Sep 25, 2026 | A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContent... |
| CVE-2026-97818 | HIGH | 8.6 | — | Sep 25, 2026 | phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php. |
| CVE-2026-97764 | LOW | 3.7 | — | Sep 25, 2026 | django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configu... |
| CVE-2026-97737 | HIGH | 7.4 | 0.3% | Sep 25, 2026 | In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leadin... |
| CVE-2026-97736 | MEDIUM | 5.4 | 0.2% | Sep 25, 2026 | tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular e... |
| CVE-2026-97735 | HIGH | 8 | — | Sep 25, 2026 | ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages ... |
| CVE-2026-97732 | MEDIUM | 5.1 | — | Sep 25, 2026 | IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for exp... |
| CVE-2026-97731 | HIGH | 7.1 | 0.2% | Sep 25, 2026 | MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied... |
| CVE-2026-97730 | HIGH | 8.5 | 1.0% | Sep 25, 2026 | In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dash... |
| CVE-2026-97724 | MEDIUM | 4.3 | — | Sep 25, 2026 | A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlle... |
| CVE-2026-97650 | MEDIUM | 4.3 | — | Sep 25, 2026 | A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. A... |
| CVE-2026-97723 | MEDIUM | 5.4 | — | Sep 25, 2026 | madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering fu... |
| CVE-2026-97649 | MEDIUM | 4.7 | 0.2% | Sep 25, 2026 | A flaw has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected b... |
| CVE-2026-97648 | MEDIUM | 4.3 | 0.2% | Sep 25, 2026 | A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Aff... |
| CVE-2026-97647 | MEDIUM | 5.3 | — | Sep 25, 2026 | A security vulnerability has been detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207c... |
| CVE-2026-95811 | MEDIUM | 6.5 | 0.4% | Sep 25, 2026 | Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now