2026 CVE Vulnerabilities
48,299 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39835 | MEDIUM | 5.3 | 0.5% | May 22, 2026 | SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be c... |
| CVE-2026-39828 | MEDIUM | 6.3 | 0.4% | May 22, 2026 | When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were... |
| CVE-2026-39827 | MEDIUM | 6.5 | 0.2% | May 22, 2026 | An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory gr... |
| CVE-2026-8435 | MEDIUM | 6.5 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file appr... |
| CVE-2026-8337 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in s... |
| CVE-2026-8327 | MEDIUM | 4.3 | 0.2% | May 21, 2026 | Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass... |
| CVE-2026-8245 | MEDIUM | 5.4 | 0.1% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\... |
| CVE-2026-8240 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across every page with a configur... |
| CVE-2026-8239 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating' endpoint confirms exist... |
| CVE-2026-8238 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page' endpoint returns the ... |
| CVE-2026-8237 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations/message_detail` endpoint returns th... |
| CVE-2026-8236 | MEDIUM | 4.3 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate. The endpoint /ccm/system... |
| CVE-2026-8139 | MEDIUM | 5.4 | 0.1% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because updateCollectionAliasExte... |
| CVE-2026-7890 | MEDIUM | 6.4 | 0.2% | May 21, 2026 | In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor and fetches it server-s... |
| CVE-2026-7887 | MEDIUM | 6.4 | 0.2% | May 21, 2026 | For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A user with uIsActive=0 ... |
| CVE-2026-7886 | MEDIUM | 4.3 | 0.3% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[] parameter which can lea... |
| CVE-2026-7882 | MEDIUM | 4.3 | 0.1% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF token check in the Del... |
| CVE-2026-7881 | MEDIUM | 4.3 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block via... |
| CVE-2026-7879 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | In Concrete CMS 9.5.0 and below, the submit_password() method in concrete/controllers/single_page/download_file.php all... |
| CVE-2026-5091 | MEDIUM | 5.1 | 0.2% | May 21, 2026 | Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks. These versions us... |
| CVE-2026-4929 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term... |
| CVE-2026-4093 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline. Ve... |
| CVE-2026-22678 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the ... |
| CVE-2026-8205 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does no... |
| CVE-2026-8204 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now