2026 CVE Vulnerabilities

48,299 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-39835MEDIUM5.3SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be c...
CVE-2026-39828MEDIUM6.3When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were...
CVE-2026-39827MEDIUM6.5An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory gr...
CVE-2026-8435MEDIUM6.5Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file appr...
CVE-2026-8337MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in s...
CVE-2026-8327MEDIUM4.3Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass...
CVE-2026-8245MEDIUM5.4Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\...
CVE-2026-8240MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configur...
CVE-2026-8239MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms exist...
CVE-2026-8238MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' endpoint returns the ...
CVE-2026-8237MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns th...
CVE-2026-8236MEDIUM4.3Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system...
CVE-2026-8139MEDIUM5.4Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExte...
CVE-2026-7890MEDIUM6.4In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-s...
CVE-2026-7887MEDIUM6.4For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 ...
CVE-2026-7886MEDIUM4.3Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lea...
CVE-2026-7882MEDIUM4.3Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF token check in the Del...
CVE-2026-7881MEDIUM4.3Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via...
CVE-2026-7879MEDIUM5.3In Concrete CMS 9.5.0 and below,  the submit_password() method in concrete/controllers/single_page/download_file.php all...
CVE-2026-5091MEDIUM5.1Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions us...
CVE-2026-4929MEDIUM5.4Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term...
CVE-2026-4093MEDIUM5.4In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Ve...
CVE-2026-22678MEDIUM5.4Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the ...
CVE-2026-8205MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does no...
CVE-2026-8204MEDIUM5.3Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now