2026 CVE Vulnerabilities

64,704 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-100867LOW3.3spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before renderi...
CVE-2026-100866LOW3.3onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, ...
CVE-2026-94417LOW2.3When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL ski...
CVE-2026-15442LOW2.3In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS ...
CVE-2026-94419LOW2.3Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of th...
CVE-2026-94418LOW2.3Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse t...
CVE-2026-100837LOW3.7Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration...
CVE-2026-100649LOW3.7vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler sub...
CVE-2026-100620LOW3.8Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onb...
CVE-2026-100311LOW3.5A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be...
CVE-2026-96526LOW2.7The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one ...
CVE-2026-96525LOW2.7The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check...
CVE-2026-100573LOW3.3OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allow...
CVE-2026-100542LOW3.1OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill i...
CVE-2026-100539LOW2.6OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memor...
CVE-2026-100537LOW3.1OpenClaw (npm package 'openclaw') before 2026.8.1 fails to apply the originating requester's effective tool policy durin...
CVE-2026-100534LOW3.1OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that al...
CVE-2026-100503LOW3.3Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter f...
CVE-2026-100417LOW3.1RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests,...
CVE-2026-97897LOW3.5A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the...
CVE-2026-97896LOW3.5A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationF...
CVE-2026-63204LOW2.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent per...
CVE-2026-65828LOW2.3Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on At...
CVE-2026-56730LOW2.1Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerabilit...
CVE-2026-67420LOW2.3RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ OAu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now