2026 CVE Vulnerabilities

43,225 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-13939LOW3.1Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 150.0.7871.47 allowed a remo...
CVE-2026-58371LOW3.1SeaweedFS before 4.30 reflects the callback query parameter verbatim into responses served with Content-Type application...
CVE-2026-10654LOW3.1A race condition in the Zephyr Bluetooth Classic RFCOMM host stack (subsys/bluetooth/host/classic/rfcomm.c) mishandles a...
CVE-2026-13758LOW3.7CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt...
CVE-2026-53427LOW2.3Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leandrocp MDEx all...
CVE-2026-13587LOW3.7A vulnerability was found in seladb PcapPlusPlus 25.05. The affected element is the function parse_by_block_type of the ...
CVE-2026-13574LOW3.3A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr i...
CVE-2026-13573LOW3.3A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the li...
CVE-2026-13570LOW3.5A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the f...
CVE-2026-13558LOW3.5A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown proces...
CVE-2026-13523LOW3.3A weakness has been identified in GPAC up to 26.02.0. This affects an unknown part of the file src/utils/base_encoding.c...
CVE-2026-13514LOW2.4A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown proc...
CVE-2026-13511LOW3.1A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversa...
CVE-2026-13510LOW3.7A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in...
CVE-2026-13504LOW3.5A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code o...
CVE-2026-13493LOW3.1A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file ba...
CVE-2026-13491LOW3.7A vulnerability was detected in 78 xiaozhi-esp32 up to 2.2.6. This vulnerability affects the function Application::GetIn...
CVE-2026-13489LOW3.1A weakness has been identified in 78 xiaozhi-esp32 up to 2.2.6. Affected by this issue is the function ParseMessage of t...
CVE-2026-13483LOW3.1A flaw has been found in arc53 DocsGPT up to 0.18.0. The affected element is the function encrypt_credentials of the fil...
CVE-2026-13482LOW3.7A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file...
CVE-2026-10644LOW3.1The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mchp_sercom_g1.c), used by the PIC32CM-JH SoC family, contains ...
CVE-2026-47206LOW2.3Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Proto...
CVE-2026-3472LOW3.5Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image render...
CVE-2026-57940LOW2.1HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The functi...
CVE-2026-48936LOW3.3A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now