2026 CVE Vulnerabilities

43,225 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-47199LOW2.3Frappe is a full-stack web application framework. Prior to 16.18.3 and 15.108.0, check_safe_sql_query permitted SELECT I...
CVE-2026-13235LOW3.3Missing Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Forceful Browsing. This issue affects ...
CVE-2026-13233LOW3.3Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issu...
CVE-2026-13232LOW3.1Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing....
CVE-2026-11909LOW3.3Missing Authorization vulnerability in Drupal Examples for Developers allows Forceful Browsing. This issue affects Examp...
CVE-2026-55671LOW2.3ZITADEL is an open source identity management platform. From 4.0.0-rc.1 through 4.15.1, ZITADEL's HTTP notification chan...
CVE-2026-55670LOW2.3ZITADEL is an open source identity management platform. Prior to 4.15.1, ZITADEL's event store validation can retain the...
CVE-2026-59180LOW3.1Apprise is an open source library which allows you to send a notification to almost all of the most popular notification...
CVE-2026-55783LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's seven in-hous...
CVE-2026-55782LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's WebAssembly a...
CVE-2026-55781LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's UFS and FFS i...
CVE-2026-55780LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET single-f...
CVE-2026-59791LOW3.5In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
CVE-2026-56813LOW2.1Improper Neutralization of Parameter/Argument Delimiters vulnerability in elixir-plug plug allows an attacker to inject ...
CVE-2026-58225LOW2.1SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject...
CVE-2026-15028LOW3.9A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a sp...
CVE-2026-15326LOW3.8A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the f...
CVE-2026-15321LOW2.4A vulnerability was found in MyEMS up to 6.4.0. The affected element is the function on_post of the file myems-api/core/...
CVE-2026-15311LOW3.5A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function Ma...
CVE-2026-15276LOW3.3A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metad...
CVE-2026-15274LOW3.3A vulnerability was detected in lo48576 fbxcel up to 0.9.0. This affects an unknown part of the file src/pull_parser/v74...
CVE-2026-59215LOW3.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread pa...
CVE-2026-15194LOW3.3A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/co...
CVE-2026-15185LOW3.3A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools...
CVE-2026-15184LOW3.3A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now