2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-91746 | MEDIUM | 4.3 | 0.2% | Sep 15, 2026 | Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin... |
| CVE-2026-91744 | MEDIUM | 5.3 | 0.2% | Sep 15, 2026 | Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who ha... |
| CVE-2026-91742 | MEDIUM | 4.8 | 0.2% | Sep 15, 2026 | Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging ... |
| CVE-2026-91740 | MEDIUM | 4.3 | 0.2% | Sep 15, 2026 | Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin ... |
| CVE-2026-91739 | MEDIUM | 4.2 | 0.2% | Sep 15, 2026 | Missing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had... |
| CVE-2026-91726 | MEDIUM | 4.7 | 0.2% | Sep 15, 2026 | Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memo... |
| CVE-2026-91725 | MEDIUM | 5.3 | 0.2% | Sep 15, 2026 | Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive inform... |
| CVE-2026-91720 | MEDIUM | 4.7 | 0.2% | Sep 15, 2026 | Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside... |
| CVE-2026-91717 | MEDIUM | 5.1 | 0.1% | Sep 15, 2026 | Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtai... |
| CVE-2026-91714 | MEDIUM | 5.3 | 0.2% | Sep 15, 2026 | Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engi... |
| CVE-2026-91713 | MEDIUM | 4.2 | 0.2% | Sep 15, 2026 | Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised t... |
| CVE-2026-81927 | MEDIUM | 5.4 | 0.3% | Sep 15, 2026 | Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processin... |
| CVE-2026-81926 | MEDIUM | 6.1 | 0.4% | Sep 15, 2026 | Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's dupli... |
| CVE-2026-68953 | MEDIUM | 6.5 | 0.4% | Sep 15, 2026 | The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclos... |
| CVE-2026-66372 | MEDIUM | 6.8 | 0.2% | Sep 15, 2026 | The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding toke... |
| CVE-2026-19655 | MEDIUM | 6.5 | 0.2% | Sep 15, 2026 | On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with ... |
| CVE-2026-18426 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control... |
| CVE-2026-89027 | MEDIUM | 6.5 | 0.4% | Sep 15, 2026 | miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downg... |
| CVE-2026-88922 | MEDIUM | 6.7 | 0.1% | Sep 15, 2026 | The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decomp... |
| CVE-2026-88743 | MEDIUM | 6.1 | 0.3% | Sep 15, 2026 | Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags. |
| CVE-2026-88742 | MEDIUM | 5.4 | 0.2% | Sep 15, 2026 | Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field. |
| CVE-2026-87285 | MEDIUM | 6 | 0.2% | Sep 15, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-87283 | MEDIUM | 6 | 0.1% | Sep 15, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-87282 | MEDIUM | 6 | 0.2% | Sep 15, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-87280 | MEDIUM | 4.2 | 0.1% | Sep 15, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now