2026 CVE Vulnerabilities

43,225 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-59269LOW3.8A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in ...
CVE-2026-54780LOW3.7CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ...
CVE-2026-15115LOW3.3Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed...
CVE-2026-15168LOW3.3BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure
CVE-2026-6352LOW2.7GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19....
CVE-2026-57481LOW2.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a...
CVE-2026-55778LOW2.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a...
CVE-2026-14967LOW3.1BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory...
CVE-2026-14966LOW3.1BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it fa...
CVE-2026-53480LOW2.7Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-15041LOW3.7A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for co...
CVE-2026-59153LOW2.1Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve me...
CVE-2026-28378LOW2.7The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organizatio...
CVE-2026-55592LOW3.9Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and a...
CVE-2026-14935LOW3.7A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverte...
CVE-2026-42201LOW3.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-27844LOW2.7Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated...
CVE-2026-27790LOW2.7Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by ...
CVE-2026-42172LOW3.1Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-42145LOW3.1Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34149LOW3.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-53640LOW2.3FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, low-privileged staff ac...
CVE-2026-43928LOW2.3FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the PayPalEmail payment...
CVE-2026-42148LOW3.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34049LOW3.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.451 ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now