2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-84355LOW3.1Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromi...
CVE-2026-84331LOW3.1Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised t...
CVE-2026-84328LOW3.1Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromise...
CVE-2026-84368LOW3.7joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/...
CVE-2026-84367LOW3.7joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/...
CVE-2026-84307LOW3.7Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5...
CVE-2026-73748LOW2.2A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privi...
CVE-2026-73747LOW2.5A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitatio...
CVE-2026-73746LOW3.1A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated ...
CVE-2026-73745LOW3.1A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to ...
CVE-2026-73744LOW3.5A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that co...
CVE-2026-73743LOW3.7A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated r...
CVE-2026-81846LOW3.5An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an ...
CVE-2026-52295LOW2.9FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-ba...
CVE-2026-82748LOW2.1Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while computing i...
CVE-2026-82744LOW2.1Not Failing Securely (Failing Open) vulnerability in ash-project ash skips an Ash.Reactor change when the guard controll...
CVE-2026-82743LOW2.1Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a scheduler thread...
CVE-2026-82741LOW2.1Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the stored type...
CVE-2026-82740LOW2.1Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a doubly-nest...
CVE-2026-82739LOW2.1Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the stored value...
CVE-2026-82736LOW2.1Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-in...
CVE-2026-82734LOW2.1Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to submit a non-f...
CVE-2026-82731LOW2.3URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who c...
CVE-2026-48932LOW3.7A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild ou...
CVE-2026-18743LOW2.5A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now