2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-91746MEDIUM4.3Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin...
CVE-2026-91744MEDIUM5.3Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who ha...
CVE-2026-91742MEDIUM4.8Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging ...
CVE-2026-91740MEDIUM4.3Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin ...
CVE-2026-91739MEDIUM4.2Missing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had...
CVE-2026-91726MEDIUM4.7Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memo...
CVE-2026-91725MEDIUM5.3Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive inform...
CVE-2026-91720MEDIUM4.7Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside...
CVE-2026-91717MEDIUM5.1Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtai...
CVE-2026-91714MEDIUM5.3Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engi...
CVE-2026-91713MEDIUM4.2Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised t...
CVE-2026-81927MEDIUM5.4Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processin...
CVE-2026-81926MEDIUM6.1Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's dupli...
CVE-2026-68953MEDIUM6.5The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclos...
CVE-2026-66372MEDIUM6.8The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding toke...
CVE-2026-19655MEDIUM6.5On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with ...
CVE-2026-18426MEDIUM6.5Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control...
CVE-2026-89027MEDIUM6.5miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downg...
CVE-2026-88922MEDIUM6.7The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decomp...
CVE-2026-88743MEDIUM6.1Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.
CVE-2026-88742MEDIUM5.4Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field.
CVE-2026-87285MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-87283MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-87282MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-87280MEDIUM4.2Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now