2026 CVE Vulnerabilities

43,246 CVEs published in 2026.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2026-49246LOW1.7Jellyfin is an open source self hosted media server. Prior to 10.11.10, a specifically crafted MKV file containing forge...
CVE-2026-57288LOW3.7Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter ...
CVE-2026-13140LOW1.1Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exp...
CVE-2026-10753LOW2.7The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administ...
CVE-2026-47388LOW2.3NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a low-privilege MCP token holder with kno...
CVE-2026-46554LOW2.3NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, deleted API tokens continued to authentic...
CVE-2026-46553LOW2.1NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the upload-by-URL path did not enforce NC...
CVE-2026-46549LOW2NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_s...
CVE-2026-54327LOW2.2Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi stored API keys and OAuth credentials in auth.json...
CVE-2026-54326LOW2.5Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi HTML exports render session Markdown into a static...
CVE-2026-57062LOW2.9CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM becaus...
CVE-2026-57053LOW2.5GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandl...
CVE-2026-45692LOW3.8Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and th...
CVE-2026-56376LOW3.3ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails...
CVE-2026-55654LOW3.7A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic...
CVE-2026-49460LOW3.3pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can cr...
CVE-2026-47241LOW2.1Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, se...
CVE-2026-48931LOW3.7A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent th...
CVE-2026-53663LOW3.1React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were...
CVE-2026-53540LOW3.7Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-...
CVE-2026-53538LOW3.7Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field sep...
CVE-2026-49356LOW3.6Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an a...
CVE-2026-8823LOW3.8Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests whi...
CVE-2026-8074LOW3.8Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user act...
CVE-2026-12888LOW2An HTML injection vulnerability exists in the Google Chat webhook notification  sent by Thinkst Applied Research Canaryt...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now