2026 CVE Vulnerabilities

42,999 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-11809LOW3.7The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z...
CVE-2026-6368LOW2.1Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return inva...
CVE-2026-72729LOW2Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-loca...
CVE-2026-18503LOW2.4Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume si...
CVE-2026-64941LOW2.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attack...
CVE-2026-17016LOW3.7The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amoun...
CVE-2026-14211LOW3.8The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated empl...
CVE-2026-12971LOW2.2The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowi...
CVE-2026-19382LOW2.3A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan...
CVE-2026-19380LOW2.3A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the...
CVE-2026-12372LOW3.7A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. Th...
CVE-2026-70395LOW2.1Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to f...
CVE-2026-19361LOW3.7A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode o...
CVE-2026-19352LOW3.1A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality o...
CVE-2026-17011LOW3.8The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpo...
CVE-2026-16957LOW2.7The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed ...
CVE-2026-19324LOW3.3A weakness has been identified in HelloGGX shadcn-vue-mcp up to e170e277b94235cde627803277fc8c41103a4d38. Affected by th...
CVE-2026-11742LOW3.6The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, read...
CVE-2026-19245LOW3.3A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of th...
CVE-2026-71849LOW3.7Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy H...
CVE-2026-66000LOW2.3Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, Document Follow notification generation...
CVE-2026-19230LOW3.5A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /soci...
CVE-2026-17435LOW2.5File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When th...
CVE-2026-19209LOW3.5A flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown function of the file...
CVE-2026-19208LOW3.7A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now