2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-28622LOW3.3In getQueryBuilderInternal of MediaProvider.java, there is a possible way to retrieve location metadata due to a permiss...
CVE-2026-28582LOW3.3In onCreate of ConfirmDeviceCredentialActivity.java, there is a possible unauthorized access to and modification of devi...
CVE-2026-0054LOW3.3In isCallerAllowed of WalletContextualLocationsService.kt, there is a possible way to get wallet information due to a mi...
CVE-2026-9216LOW3.5An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacke...
CVE-2026-86670LOW3.7A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/ad...
CVE-2026-69904LOW3.5Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information ...
CVE-2026-48707LOW3.1InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forg...
CVE-2026-84392LOW2.7A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all v...
CVE-2026-84389LOW3.1A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM...
CVE-2026-86644LOW3.5A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_s...
CVE-2026-73318LOW3.8XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any A...
CVE-2026-73317LOW2.7XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows lim...
CVE-2026-33920LOW3.5A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to mis...
CVE-2026-16003LOW2Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process i...
CVE-2026-82710LOW2.3Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a maliciou...
CVE-2026-76961LOW3.5SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on c...
CVE-2026-76960LOW3.5SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on c...
CVE-2026-58234LOW2.2SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nes...
CVE-2026-82584LOW2.3Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious pa...
CVE-2026-81638LOW2.1Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit sever...
CVE-2026-86505LOW3.3In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace
CVE-2026-86503LOW3.3In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source UR...
CVE-2026-86501LOW2.8In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log
CVE-2026-86491LOW3.5In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads
CVE-2026-86487LOW3.1In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canva...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now