2026 CVE Vulnerabilities

43,188 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-56193LOW3.3Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-50678LOW3.3Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-52841LOW3.1Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Google::oauth` at `application/co...
CVE-2026-52840LOW2.7Easy!Appointments is a self hosted appointment scheduler. In versions prior to 1.6.0, `Caldav::connect_to_server` at `ap...
CVE-2026-52839LOW3.3Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appoi...
CVE-2026-52838LOW2.6Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custo...
CVE-2026-15690LOW3.1A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesAr...
CVE-2026-15678LOW3.5A security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of t...
CVE-2026-44753LOW3.7SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produ...
CVE-2026-15605LOW3.1A security vulnerability has been detected in wandb 0.25.2.dev1. Affected is the function ArtifactManifestEntry.download...
CVE-2026-15594LOW3.7A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the l...
CVE-2026-9820LOW3.8Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams end...
CVE-2026-61971LOW2.7Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-pictu...
CVE-2026-15532LOW2.4A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processin...
CVE-2026-15528LOW3.3A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file k...
CVE-2026-15526LOW3.3A flaw has been found in augmnt augments-mcp-server 7.1.0. This issue affects the function scanProjectDeps of the file s...
CVE-2026-15524LOW3.3A security vulnerability has been detected in alioshr memory-bank-mcp up to 0.2.1/3.1. This affects an unknown part of t...
CVE-2026-15505LOW3.5A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra...
CVE-2026-61874LOW3.1filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, all...
CVE-2026-61448LOW2.1Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and...
CVE-2026-55807LOW3.1Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue af...
CVE-2026-47199LOW2.3Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT I...
CVE-2026-13235LOW3.3Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects ...
CVE-2026-13233LOW3.3Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issu...
CVE-2026-13232LOW3.1Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now