2026 CVE Vulnerabilities

64,732 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-89327LOW3.8The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user th...
CVE-2026-86448LOW3.7The LearnPress WordPress plugin before 4.4.7 does not perform any authentication, capability or nonce check before serv...
CVE-2026-84907LOW3.7The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) paym...
CVE-2026-84905LOW2.7The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker...
CVE-2026-82126LOW2.7The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the...
CVE-2026-92214LOW3.5A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/c...
CVE-2026-91747LOW3.1Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the rendere...
CVE-2026-91730LOW3.1Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised...
CVE-2026-91723LOW3.1Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements ...
CVE-2026-91708LOW3.1Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the rend...
CVE-2026-87284LOW3.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-87281LOW3.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-83414LOW2.5Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version tha...
CVE-2026-83413LOW1.9Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar...
CVE-2026-83369LOW3.1Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Access SDK). Supported versi...
CVE-2026-18425LOW2.7Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\Sitem...
CVE-2026-81923LOW2.7In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before saving...
CVE-2026-81922LOW2.7Concrete CMS before 9.5.3 did not enforce a per-page authorization check when reordering pages from the sitemap. In the ...
CVE-2026-68534LOW2.3Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in sto...
CVE-2026-68533LOW2.3Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported files into the file manager before evaluatin...
CVE-2026-68532LOW2.3Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in c...
CVE-2026-68531LOW2.1Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file m...
CVE-2026-68530LOW2.1Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area...
CVE-2026-68529LOW2.1Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard act...
CVE-2026-18421LOW2.1Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboar...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now