2026 CVE Vulnerabilities

43,246 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-48936LOW3.3A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--...
CVE-2026-48935LOW3.3A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with ...
CVE-2026-13322LOW3.8A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Re...
CVE-2026-13350LOW2.3Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't b...
CVE-2026-48940LOW3.4A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field ...
CVE-2026-57588LOW3.3A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by ...
CVE-2026-57535LOW2.1Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src ...
CVE-2026-57534LOW2.1Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.
CVE-2026-57533LOW2.1Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since...
CVE-2026-57234LOW2.6Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse opti...
CVE-2026-13314LOW2Malicious HTML content could be injected into the content rendered by the pretix-digital plugin.
CVE-2026-12755LOW2.7Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows ...
CVE-2026-42004LOW3.7An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten ...
CVE-2026-40208LOW3.7An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame...
CVE-2026-40011LOW3.7An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a...
CVE-2026-56130LOW2"Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie ...
CVE-2026-45188LOW2.4Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.15.0. ...
CVE-2026-3176LOW3.1GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19....
CVE-2026-12635LOW3.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 1...
CVE-2026-0934LOW3.8GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19....
CVE-2026-49979LOW2.7Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send...
CVE-2026-39894LOW2.5Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent d...
CVE-2026-52796LOW3.5Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic...
CVE-2026-49277LOW2.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, ...
CVE-2026-45757LOW2.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now