2026 CVE Vulnerabilities

43,188 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-16203LOW3.5A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u...
CVE-2026-16202LOW3.5A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i...
CVE-2026-16156LOW3.5A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown par...
CVE-2026-16155LOW3.5A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u...
CVE-2026-54335LOW3.7Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and ...
CVE-2026-54244LOW3.5Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endp...
CVE-2026-48978LOW2.1oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's ...
CVE-2026-50185LOW2RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-...
CVE-2026-16073LOW3.5A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function S...
CVE-2026-21764LOW3.1HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restric...
CVE-2026-21762LOW3.7HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections ag...
CVE-2026-15997LOW1.7Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffer...
CVE-2026-62994LOW3.7CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreD...
CVE-2026-47088LOW3.1An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsi...
CVE-2026-47087LOW3.5An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A...
CVE-2026-47086LOW3.5An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authe...
CVE-2026-47081LOW3.1An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence orac...
CVE-2026-44969LOW3.3dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/...
CVE-2026-15945LOW2.7A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin ...
CVE-2026-35145LOW3.1HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to ...
CVE-2026-12907LOW2.7The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions,...
CVE-2026-12906LOW2.7The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a r...
CVE-2026-38755LOW2.9A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Ser...
CVE-2026-38752LOW2.9A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial ...
CVE-2026-15921LOW3.1Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now