2026 CVE Vulnerabilities
64,732 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-89327 | LOW | 3.8 | 0.2% | Sep 16, 2026 | The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user th... |
| CVE-2026-86448 | LOW | 3.7 | 0.2% | Sep 16, 2026 | The LearnPress WordPress plugin before 4.4.7 does not perform any authentication, capability or nonce check before serv... |
| CVE-2026-84907 | LOW | 3.7 | 0.2% | Sep 16, 2026 | The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) paym... |
| CVE-2026-84905 | LOW | 2.7 | 0.2% | Sep 16, 2026 | The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker... |
| CVE-2026-82126 | LOW | 2.7 | 0.2% | Sep 16, 2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the... |
| CVE-2026-92214 | LOW | 3.5 | 0.3% | Sep 16, 2026 | A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/c... |
| CVE-2026-91747 | LOW | 3.1 | 0.2% | Sep 15, 2026 | Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the rendere... |
| CVE-2026-91730 | LOW | 3.1 | 0.2% | Sep 15, 2026 | Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised... |
| CVE-2026-91723 | LOW | 3.1 | 0.2% | Sep 15, 2026 | Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements ... |
| CVE-2026-91708 | LOW | 3.1 | 0.2% | Sep 15, 2026 | Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the rend... |
| CVE-2026-87284 | LOW | 3.2 | 0.1% | Sep 15, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-87281 | LOW | 3.2 | 0.1% | Sep 15, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-83414 | LOW | 2.5 | 0.1% | Sep 15, 2026 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version tha... |
| CVE-2026-83413 | LOW | 1.9 | 0.1% | Sep 15, 2026 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar... |
| CVE-2026-83369 | LOW | 3.1 | 0.2% | Sep 15, 2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Access SDK). Supported versi... |
| CVE-2026-18425 | LOW | 2.7 | 0.2% | Sep 15, 2026 | Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\Sitem... |
| CVE-2026-81923 | LOW | 2.7 | 0.2% | Sep 15, 2026 | In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before saving... |
| CVE-2026-81922 | LOW | 2.7 | 0.2% | Sep 15, 2026 | Concrete CMS before 9.5.3 did not enforce a per-page authorization check when reordering pages from the sitemap. In the ... |
| CVE-2026-68534 | LOW | 2.3 | 0.4% | Sep 15, 2026 | Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in sto... |
| CVE-2026-68533 | LOW | 2.3 | 0.3% | Sep 15, 2026 | Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported files into the file manager before evaluatin... |
| CVE-2026-68532 | LOW | 2.3 | 0.2% | Sep 15, 2026 | Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in c... |
| CVE-2026-68531 | LOW | 2.1 | 0.3% | Sep 15, 2026 | Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file m... |
| CVE-2026-68530 | LOW | 2.1 | 0.3% | Sep 15, 2026 | Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area... |
| CVE-2026-68529 | LOW | 2.1 | 0.2% | Sep 15, 2026 | Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard act... |
| CVE-2026-18421 | LOW | 2.1 | 0.2% | Sep 15, 2026 | Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboar... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now