2026 CVE Vulnerabilities

64,755 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-86424LOW2.5ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decod...
CVE-2026-86422LOW3.3ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows tha...
CVE-2026-86301LOW3.5A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the ...
CVE-2026-82312LOW1.8OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial ...
CVE-2026-81738LOW2.3OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write ...
CVE-2026-86231LOW3.7A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src...
CVE-2026-86227LOW3.1A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of t...
CVE-2026-86226LOW3.5A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown...
CVE-2026-86181LOW3.5A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functional...
CVE-2026-84927LOW2.7The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Rev...
CVE-2026-84926LOW2.7The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST route...
CVE-2026-84745LOW2.7The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read ...
CVE-2026-84225LOW2.2The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before ...
CVE-2026-81348LOW3.7The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthentic...
CVE-2026-78150LOW2.7The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to du...
CVE-2026-86141LOW3.3xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., i...
CVE-2026-85704LOW3.7A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This i...
CVE-2026-18540LOW3.7undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier par...
CVE-2026-17483LOW3.3IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives ...
CVE-2026-85592LOW3.7phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddin...
CVE-2026-84066LOW3.1The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify th...
CVE-2026-85406LOW3.5A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the compon...
CVE-2026-85405LOW3.5A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/roleAdd...
CVE-2026-45197LOW2.5Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read...
CVE-2026-85458LOW2.1Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now