2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-85458LOW2.1Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.
CVE-2026-85207LOW3.5A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of t...
CVE-2026-85052LOW3.1Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromis...
CVE-2026-49456LOW3.1Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported from waku/ro...
CVE-2026-84969LOW3.7A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes...
CVE-2026-85030LOW3.7A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32ced735adf7c19ed8175adb1c8df. The affected element i...
CVE-2026-85022LOW3.5A vulnerability was identified in langgenius dify 1.13.0. Affected by this vulnerability is the function router.replace ...
CVE-2026-84653LOW3.5Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform pe...
CVE-2026-63020LOW3.1A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error mes...
CVE-2026-78600LOW3.5Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (C...
CVE-2026-78587LOW3.1Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privile...
CVE-2026-19698LOW3.5The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using ...
CVE-2026-14326LOW3.8The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through it...
CVE-2026-81168LOW3.7Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functiona...
CVE-2026-81161LOW3.3Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalati...
CVE-2026-81159LOW3.7Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commer...
CVE-2026-81198LOW3.8The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum ...
CVE-2026-81196LOW2.7The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question...
CVE-2026-77787LOW2.7The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target...
CVE-2026-77785LOW2.7The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the spe...
CVE-2026-77784LOW2.7The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modif...
CVE-2026-77783LOW3.7The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front en...
CVE-2026-84438LOW3.5A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/control...
CVE-2026-84437LOW3.5A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/c...
CVE-2026-84359LOW3.1Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the rende...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now