2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90552 | MEDIUM | 4.3 | 0.2% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlist... |
| CVE-2026-90551 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_fr... |
| CVE-2026-90550 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins... |
| CVE-2026-90549 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndr... |
| CVE-2026-90548 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGalle... |
| CVE-2026-90547 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark p... |
| CVE-2026-90546 | MEDIUM | 4.3 | 0.2% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the li... |
| CVE-2026-90545 | MEDIUM | 4.3 | 0.2% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the co... |
| CVE-2026-90544 | MEDIUM | 4.3 | 0.2% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the vi... |
| CVE-2026-90543 | MEDIUM | 5.3 | 0.3% | Sep 12, 2026 | WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a mis... |
| CVE-2026-90542 | MEDIUM | 5.4 | 0.1% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access li... |
| CVE-2026-90541 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMen... |
| CVE-2026-90540 | MEDIUM | 4.3 | 0.2% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListA... |
| CVE-2026-90539 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in t... |
| CVE-2026-90538 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in pl... |
| CVE-2026-90536 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoin... |
| CVE-2026-90534 | MEDIUM | 6.5 | 0.2% | Sep 12, 2026 | Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/no... |
| CVE-2026-90533 | MEDIUM | 6.5 | 0.2% | Sep 12, 2026 | Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any auth... |
| CVE-2026-10148 | MEDIUM | 6.4 | 0.3% | Sep 12, 2026 | The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via m... |
| CVE-2026-90474 | MEDIUM | 6.8 | 0.3% | Sep 12, 2026 | MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server wher... |
| CVE-2026-90473 | MEDIUM | 5.3 | 0.2% | Sep 12, 2026 | msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MA... |
| CVE-2026-90472 | MEDIUM | 5.3 | 0.3% | Sep 12, 2026 | msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively de... |
| CVE-2026-89172 | MEDIUM | 5.6 | 0.2% | Sep 12, 2026 | Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052... |
| CVE-2026-85198 | MEDIUM | 6.5 | 0.3% | Sep 12, 2026 | The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic S... |
| CVE-2026-77161 | MEDIUM | 6.5 | 0.3% | Sep 12, 2026 | The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now