2026 CVE Vulnerabilities

64,755 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-0054LOW3.3In isCallerAllowed of WalletContextualLocationsService.kt, there is a possible way to get wallet information due to a mi...
CVE-2026-9216LOW3.5An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacke...
CVE-2026-86670LOW3.7A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/ad...
CVE-2026-69904LOW3.5Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information ...
CVE-2026-48707LOW3.1InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forg...
CVE-2026-84392LOW2.7A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all v...
CVE-2026-84389LOW3.1A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM...
CVE-2026-86644LOW3.5A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_s...
CVE-2026-73318LOW3.8XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any A...
CVE-2026-73317LOW2.7XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows lim...
CVE-2026-33920LOW3.5A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to mis...
CVE-2026-16003LOW2Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process i...
CVE-2026-82710LOW2.3Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a maliciou...
CVE-2026-76961LOW3.5SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on c...
CVE-2026-76960LOW3.5SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on c...
CVE-2026-58234LOW2.2SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nes...
CVE-2026-82584LOW2.3Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious pa...
CVE-2026-81638LOW2.1Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit sever...
CVE-2026-86505LOW3.3In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace
CVE-2026-86503LOW3.3In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source UR...
CVE-2026-86501LOW2.8In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log
CVE-2026-86491LOW3.5In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads
CVE-2026-86487LOW3.1In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canva...
CVE-2026-86486LOW3.7In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank
CVE-2026-86485LOW3.3In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now